Vulnerability Disclosure Policy

Last updated August 29, 2026 · Version 1.0

Contents

LATO welcomes reports from security researchers and customers. If you believe you have found a vulnerability in a LATO system, tell us and we will work with you to understand and fix it. This is the policy referenced by our security.txt (RFC 9116).

Scope

In scope: any system operated by LATO under latolabs.io or latotec.io, including the web app, the admin console, the API, the Excel add-in and this website.

Out of scope:

  • Infrastructure operated by our subprocessors (Supabase, Railway, Vercel, Anthropic and others). Report those to the provider concerned.
  • Denial of service, volumetric or resource-exhaustion testing, and automated scanning at a rate that degrades the service.
  • Social engineering of LATO staff or customers, phishing, and physical attacks.
  • Findings that require an already-compromised customer account or device.
  • Output from automated tools without a demonstrated impact, and best-practice observations with no security consequence (missing headers on static assets, version disclosure, email authentication opinions).

How to report

Email security@latolabs.io. Include enough for us to reproduce the issue: the affected URL or component, steps to reproduce, the impact you believe it has, and, if relevant, the account you used. Keep the report to what is needed to demonstrate the issue.

What we commit to

  • We acknowledge your report within 3 business days.
  • We keep you informed while we triage and fix the issue, and we tell you when the fix is deployed.
  • We remediate confirmed findings within the targets set in our security policies: critical within 7 days, high within 30 days, medium within 90 days, low on a best-effort basis.
  • We credit you for the finding once it is fixed, if you want us to.
  • We do not currently run a paid bug bounty program.

What we ask of you

  • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of the service.
  • Access, modify or retain only the data needed to demonstrate the issue. If you encounter personal data or another customer’s data, stop, do not download it, and tell us in the report.
  • Do not exploit a finding beyond a proof of concept, and do not pivot to other systems.
  • Give us reasonable time to fix the issue before disclosing it publicly: 90 days from your report, or when the fix ships, whichever comes first. We are happy to agree a different timeline for a complex fix.

Safe harbor

We will not pursue or support legal action against you for good-faith security research that complies with this policy. This policy does not authorize activity that breaks the law, and it cannot bind third parties, including our subprocessors.

Contact

security@latolabs.io, monitored by the founders. Our current contact details and the location of this policy are published at /.well-known/security.txt.