Copacetic
Back to home

Vulnerability Disclosure Policy

Last updated 29 August 2026 — draft, pending solicitor review

We take the security of Copacetic and our customers' data seriously. This policy explains how to report a security vulnerability to us, what you can expect from that process, and the ground rules for responsible, good-faith security research against our systems.

1. How to report

Email security@copacetic.legal with a clear description of the issue, the steps to reproduce it, and its potential impact. Include any proof-of-concept material needed to understand the report — screenshots, request/response logs, or a minimal script.

Please do not include real client or personal data in your report. If a vulnerability exposed such data during testing, describe what you saw without pasting the data itself, and let us know so we can investigate.

2. What to expect from us

We aim to acknowledge every report within one business day, and to give you an initial assessment — including whether we can reproduce the issue — within five business days.

We will keep you informed of remediation progress and let you know once a fix has shipped. We're happy to credit researchers who ask to be credited, once a fix is live.

3. Scope

In scope: copacetic.legal and its subdomains, and the Copacetic web application itself.

Out of scope: third-party services we integrate with (Stripe, Supabase, Cloudflare, Google/Gemini, Resend, Vercel) — report those directly to the relevant provider. Also out of scope: social engineering or phishing against our staff or customers, physical security, and denial-of-service testing.

4. Ground rules for testing

Only test against accounts and data you own or have explicit permission to test with — never a real customer's workspace. Do not access, modify, or delete data that isn't yours. Do not run automated scanners at a volume that could degrade service for real users.

Stop and report as soon as you've established a vulnerability exists — you don't need to demonstrate maximum impact (for example, downloading an entire database) to prove a finding is real.

5. Safe harbor

We will not pursue legal action against, or refer to law enforcement, anyone who makes a good-faith effort to comply with this policy while researching or reporting a vulnerability. This safe harbor does not extend to testing that violates the ground rules above, or to the discovery, use, or disclosure of a vulnerability through any means other than the process described here.

This policy sits alongside our published security.txt file (/.well-known/security.txt), which points here as our disclosure policy. Report a vulnerability at security@copacetic.legal.