Vulnerability Disclosure Policy
Last updated August 29, 2026 · Version 1.0
LATO welcomes reports from security researchers and customers. If you believe you have found
a vulnerability in a LATO system, tell us and we will work with you to understand and fix it.
This is the policy referenced by our security.txt (RFC 9116).
Scope
In scope: any system operated by LATO under latolabs.io or latotec.io, including the web
app, the admin console, the API, the Excel add-in and this website.
Out of scope:
- Infrastructure operated by our subprocessors (Supabase, Railway,
Vercel, Anthropic and others). Report those to the provider concerned.
- Denial of service, volumetric or resource-exhaustion testing, and automated scanning at a
rate that degrades the service.
- Social engineering of LATO staff or customers, phishing, and physical attacks.
- Findings that require an already-compromised customer account or device.
- Output from automated tools without a demonstrated impact, and best-practice observations
with no security consequence (missing headers on static assets, version disclosure, email
authentication opinions).
How to report
Email security@latolabs.io. Include enough for us to
reproduce the issue: the affected URL or component, steps to reproduce, the impact you believe
it has, and, if relevant, the account you used. Keep the report to what is needed to
demonstrate the issue.
What we commit to
- We acknowledge your report within 3 business days.
- We keep you informed while we triage and fix the issue, and we tell you when the fix is
deployed.
- We remediate confirmed findings within the targets set in our security policies:
critical within 7 days, high within 30 days, medium within 90 days, low on a best-effort
basis.
- We credit you for the finding once it is fixed, if you want us to.
- We do not currently run a paid bug bounty program.
What we ask of you
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption or
degradation of the service.
- Access, modify or retain only the data needed to demonstrate the issue. If you encounter
personal data or another customer’s data, stop, do not download it, and tell us in the
report.
- Do not exploit a finding beyond a proof of concept, and do not pivot to other systems.
- Give us reasonable time to fix the issue before disclosing it publicly: 90 days from your
report, or when the fix ships, whichever comes first. We are happy to agree a different
timeline for a complex fix.
Safe harbor
We will not pursue or support legal action against you for good-faith security research that
complies with this policy. This policy does not authorize activity that breaks the law, and it
cannot bind third parties, including our subprocessors.
security@latolabs.io, monitored by the founders. Our current
contact details and the location of this policy are published at
/.well-known/security.txt.