Security & Responsible Disclosure
Found something? Tell us first, follow the rules below, and we will treat your research as authorised.
Effective September 2, 2026 · Last updated September 2, 2026
1. Reporting a Vulnerability
If you believe you have found a security vulnerability in Coach Manuals, please tell us before you tell anyone else. Email contact@coachmanuals.com with "Security" in the subject line.
A useful report includes:
- the affected URL, endpoint or feature;
- a clear description of the issue and its impact;
- the steps needed to reproduce it, including any request or payload;
- any proof-of-concept material, screenshots or logs; and
- how you would like to be credited, if you would like to be.
We aim to acknowledge reports within 3 business days, to give an initial assessment within 10 business days, and to keep you updated until the issue is resolved.
2. Safe Harbour for Good-Faith Research
If you make a good-faith effort to comply with this policy during your research, we will:
- consider your research authorised under the Computer Fraud and Abuse Act and comparable state law, and not pursue or support a civil or criminal action against you for it;
- treat your report as an authorised activity for the purposes of any anti-circumvention claim under the Digital Millennium Copyright Act; and
- work with you to understand and resolve the issue quickly.
If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make this authorisation known.
This safe harbour does not apply to activity that breaks the rules below, and it cannot bind third parties whose systems you may reach through ours.
3. Rules of Engagement
When testing, you must not:
- access, modify, delete or exfiltrate data that is not yours — use your own test account;
- perform denial-of-service, volumetric, load or stress testing;
- send unsolicited messages, including phishing or social engineering of our users, staff or providers;
- test the physical security of any facility, or the systems of our providers;
- use automated scanners that generate substantial traffic against production;
- publicly disclose the issue before we have fixed it and agreed a timeline with you; or
- demand payment in exchange for withholding disclosure.
If you inadvertently access data belonging to someone else, stop immediately, do not save or share it, and tell us in your report.
4. Scope
In scope: the main web application and its APIs, authentication and session handling, access control between accounts, the public manual and check-in link mechanism, file upload handling, and billing flows.
Out of scope: findings from automated scanners without a demonstrated impact; missing best-practice headers with no exploitable consequence; rate limiting on non-sensitive endpoints; email configuration issues such as SPF, DKIM or DMARC without a working spoofing proof; version-disclosure banners; vulnerabilities requiring a rooted or compromised device, physical access, or a highly improbable user interaction; social engineering; and issues in third-party services, which should be reported to those providers directly.
5. Rewards
We do not currently operate a paid bug-bounty programme, and we cannot guarantee financial compensation.
We are glad to acknowledge researchers publicly with their permission, and we will always respond to a good report with a real answer rather than silence.
6. How We Protect the Platform
A description of the technical and organisational measures we maintain is published in Annex II of our Data Processing Addendum, and summarised in our Privacy Policy.
Security is an ongoing programme, not a finished state. We prioritise remediation by severity and exploitability, and we do not claim that the platform is free of vulnerabilities.
7. If Personal Data Is Affected
If we determine that a security incident has compromised personal information, we will notify affected users and any regulator as required by applicable law, including the Florida Information Protection Act. Coaches using the platform as controllers will be notified without undue delay so they can meet their own obligations. See our Privacy Policy and Data Processing Addendum.
