Back
Security
Natty Hatty — Bug Bounty & Responsible Disclosure Policy
Version: v1.0
Effective Date: November 15, 2025
Natty Hatty, Inc. (“Natty Hatty”) is committed to protecting the safety, security, and privacy of our users—especially minors.
We welcome and encourage responsible security research that helps us maintain a secure platform.
This Responsible Disclosure Policy (“Policy”) outlines how security researchers can report This Responsible Disclosure Policy (“Policy”) outlines how researchers may report vulnerabilities, what is in scope, what is out of scope, and how Natty Hatty supports good-faith security research. vulnerabilities, what is in scope, what is out of scope, and how Natty Hatty will engage with good-faith researchers.
1. Purpose
The goals of this policy are to:
Encourage responsible reporting of security vulnerabilities
Protect youth-sports organizations and minors
Provide safe-harbor for legitimate researchers
Define the boundaries of acceptable testing
Support coordinated vulnerability disclosure best practices
Natty Hatty appreciates contributions from the security community.
2. Safe Harbor (Good-Faith Protection)
Natty Hatty commits that we will not pursue legal action against researchers who:
Engage in good-faith, non-destructive security testing
Follow all rules in this Policy
Avoid accessing private user data
Do not exploit a vulnerability after discovering it
Do not publicly disclose the vulnerability before Natty Hatty confirms remediation
Promptly delete any data inadvertently accessed
Do not engage in extortion, threats, or harm
Natty Hatty will interpret testing activities constructively, not punitively.
3. How to Report a Vulnerability
Email all vulnerability reports to:
security@nattyhatty.com
Subject Line: Security Vulnerability Report
Your report should include:
Detailed description of the issue
Steps to reproduce
Affected endpoint, URL, or component
Proof-of-concept (non-destructive)
Impact assessment
Your contact information for follow-up
Natty Hatty responds to all valid reports within 5 security-business days.
4. Eligibility for Recognition / Bounty Consideration
Natty Hatty may, at our discretion, offer:
Public acknowledgment
Swag
Gift cards
Monetary awards (if and when Natty Hatty’s formal bounty program launches)
To be eligible, the report must:
Be the first to identify the issue
Demonstrate real security impact
Be submitted with clear reproduction steps
Follow this Policy fully
Note: This policy establishes Responsible Disclosure. A formal cash bug bounty program may be introduced later.
5. In-Scope Targets
The following Natty Hatty systems are in scope:
5.1 Natty Hatty Web Business Center
Organization accounts
Staff accounts
Team management
Rosters, schedules, and events
Payments pages
Dashboard and analytics
Signature workflows
5.2 Natty Hatty Customer App (iOS & Android)
Authentication
Family/guardian accounts
Payments & registrations
Signature flows
Profile management
5.3 Signature / Document System
Signing endpoints
Audit trails
PDF generation
Access validation
5.4 API Endpoints
Public APIs
Mobile APIs
Real-time endpoints
5.5 Portal & Login Systems
Password reset flows
MFA flows
Session handling
Any vulnerabilities affecting the confidentiality, integrity, or availability of user data—especially minors’ data—are high priority.
6. Out-of-Scope Items
The following items are NOT in scope:
6.1 Social Engineering
Phishing Natty Hatty employees
Impersonation attacks
Vishing or baiting
6.2 Non-Security Bugs
UI/UX issues
Typos
Performance issues
Missing accessibility features
Minor account misconfigurations
6.3 Attacks that Risk User Safety
Strictly prohibited:
Testing targeting minors’ accounts
Attempting to access private roster, player, or guardian data
Attempting to intercept live signatures or private documents
6.4 Destructive or Disruptive Activities
Not allowed:
DDoS / traffic floods
Automated scanning at high volume
Brute force attacks
Spamming
Removing or altering data
Any action that degrades system performance
6.5 Use of Automated Tools
Excessive scanning tools (e.g., Nessus, Nikto, aggressive Burp Suite scans) are out of scope unless rate-limited and non-destructive.
7. Prohibited Actions (Strict)
Researchers must not:
Access, modify, or delete real user data
Create mass accounts or spam registrations
Attempt to charge real payment methods
View or alter minors’ information
Access live rosters, schedules, or teams
Download or modify signed documents
Run automated scripts that impact real events or payments
Natty Hatty enforces a strict zero-tolerance policy to protect minors and private data.
8. What Happens After You Submit a Report
Natty Hatty follows a standard disclosure lifecycle:
1. Acknowledgment within 5 security-business days
2. Assessment of severity and validity
3. Replication of the issue internally
4. Mitigation or patching
5. Verification of fix
6. Optional credit / acknowledgment (with your permission)
We strive to remediate valid high-impact vulnerabilities quickly, often within 72 hours.
9. Public Disclosure Rules
To protect users—especially minors—Natty Hatty requires:
No public disclosure until Natty Hatty confirms the issue is fixed
No sharing of reproduction details with third parties
No publication of exploits targeting minors’ data, payments, or authentication flows
Once resolved, Natty Hatty may mutually coordinate a public write-up.
10. Legal Safe Harbor Statement
As long as researchers follow this Policy:
Natty Hatty will not pursue legal action
Natty Hatty will not involve law enforcement (except in malicious cases)
Natty Hatty will treat research as authorized under CFAA (Computer Fraud and Abuse Act)
Natty Hatty will consider actions within scope as “permitted security research”
Malicious activity, data theft, extortion, or harm to minors voids safe harbor immediately.
11. Contact
For all vulnerability and security disclosures:
security@nattyhatty.comFor urgent or high-severity findings, include the subject line:
URGENT: SECURITY VULNERABILITY