Security
Vulnerability disclosure
Last updated: 10 October 2026
If you think you've found a security issue in alcoralabs.com, please tell us. We'd rather hear about it from you than from anyone else.
How to report
Email saad@alcoralabs.com with "Security report" in the subject. Please include:
- What you found and where (URL or component).
- Steps to reproduce it.
- What an attacker could do with it.
Our machine-readable contact details are in security.txt.
Scope
In scope: the alcoralabs.com website.
Out of scope:
- Client environments. We only ever test those under a signed, written scope.
- Third-party services we use, such as our form processor and hosting provider. Please report those to the provider directly.
Ground rules
- Don't access, change or delete data that isn't yours.
- Don't run denial-of-service tests or high-volume automated scans.
- No social engineering or physical testing.
- Give us reasonable time to fix the issue before you disclose it publicly.
What we'll do
- Acknowledge your report and keep you updated while we fix it.
- Credit you publicly once it's fixed, if you'd like.
- Not pursue legal action against you for research done in good faith and within this policy.
We don't run a paid bug bounty.