← ready.coach

Security Policy

Last updated: 11 September 2026

Operated by Andre Cassal, a sole proprietor. Contact: security@ready.coach.

Ready.Coach is a white-label platform that lets independent coaches run an AI coaching assistant for the people they coach. It handles personal and often sensitive material, so we take reports seriously and would rather hear from you than not.

Reporting a vulnerability

Email security@ready.coach. Please include:

We aim to acknowledge reports within 3 business days and to keep you updated while we investigate. We are a very small team, so please allow reasonable time for a fix before disclosing publicly.

Testing: what we ask

We have no paid bug-bounty programme. We are still grateful for responsible disclosure, and we will credit you if you would like that.

When you are looking, please do not:

If you access data belonging to someone else by accident, stop, do not save it, and tell us what happened in your report. Acting in good faith under this policy, we will not pursue or support legal action against you.

Scope

In scopeNotes
ready.coachmarketing site, invite landing
api.ready.coachthe API
admin.ready.coachthe coach dashboard
Ready.Coach for iOSthe client app

Out of scope: our third-party providers' own infrastructure (Supabase, Vercel, Anthropic, Resend, Apple) — please report those to the provider directly. Also out of scope: findings from automated tooling with no demonstrated impact, missing security headers with no exploit path, and reports that amount to a difference of opinion about configuration.

staging.ready.coach and api-staging.ready.coach are pre-production environments. They are in scope, but note they hold test data rather than real coaching conversations, so impact there is generally lower.

Supported versions

Only the currently-deployed production release is supported. There are no long-lived release branches, and we do not backport fixes.

Machine-readable

This policy is referenced from /.well-known/security.txt (RFC 9116).