Security Policy
Ready.Coach is a white-label platform that lets independent coaches run an AI coaching assistant for the people they coach. It handles personal and often sensitive material, so we take reports seriously and would rather hear from you than not.
Reporting a vulnerability
Email security@ready.coach. Please include:
- a description of the issue and its impact,
- steps to reproduce, with a proof-of-concept if you have one,
- any affected URLs, accounts, or components.
We aim to acknowledge reports within 3 business days and to keep you updated while we investigate. We are a very small team, so please allow reasonable time for a fix before disclosing publicly.
Testing: what we ask
We have no paid bug-bounty programme. We are still grateful for responsible disclosure, and we will credit you if you would like that.
When you are looking, please do not:
- run automated scanners against production,
- access, modify, or exfiltrate data belonging to anyone other than yourself,
- access accounts that are not yours — coaching conversations are private, and a client's chat history is exactly the kind of data this policy exists to protect,
- perform denial-of-service testing, or anything that degrades service for real users,
- use social engineering, phishing, or physical attacks against our staff or customers.
If you access data belonging to someone else by accident, stop, do not save it, and tell us what happened in your report. Acting in good faith under this policy, we will not pursue or support legal action against you.
Scope
| In scope | Notes |
|---|---|
ready.coach | marketing site, invite landing |
api.ready.coach | the API |
admin.ready.coach | the coach dashboard |
| Ready.Coach for iOS | the client app |
Out of scope: our third-party providers' own infrastructure (Supabase, Vercel, Anthropic, Resend, Apple) — please report those to the provider directly. Also out of scope: findings from automated tooling with no demonstrated impact, missing security headers with no exploit path, and reports that amount to a difference of opinion about configuration.
staging.ready.coach and api-staging.ready.coach are
pre-production environments. They are in scope, but note they hold test data rather than
real coaching conversations, so impact there is generally lower.
Supported versions
Only the currently-deployed production release is supported. There are no long-lived release branches, and we do not backport fixes.
Machine-readable
This policy is referenced from /.well-known/security.txt (RFC 9116).