LEGAL
Responsible Disclosure
Last updated 30 July 2026
Reporting a vulnerability
We are grateful to researchers who help keep Cotesty safe. If you believe you have found a security vulnerability in this site or in the Cotesty service, please tell us at [email protected] with enough detail to reproduce it: the steps, the affected URL and the impact.
Please do
- Give us a reasonable time to investigate and fix the issue before disclosing it publicly.
- Act in good faith and avoid privacy violations, data destruction and any interruption of the service.
- Use only your own accounts and test data.
Please do not
- Access, modify or delete data that is not yours.
- Run denial-of-service attacks, spam, or social engineering against our staff or users.
- Disclose the issue publicly before we have had a chance to address it.
Our commitment
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, we will work with you to understand and fix the issue promptly, and we will credit you if you would like. We do not currently run a paid bounty programme. This scope covers cotesty.com and the subdomains we operate; third-party services we rely on are governed by their own programmes.
Contact
Security contact: [email protected].