Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty — Bug Bounty & Responsible Disclosure Policy

Version: v1.0

Effective Date: November 15, 2025

Natty Hatty, Inc. (“Natty Hatty”) is committed to protecting the safety, security, and privacy of our users—especially minors.

We welcome and encourage responsible security research that helps us maintain a secure platform.

This Responsible Disclosure Policy (“Policy”) outlines how security researchers can report This Responsible Disclosure Policy (“Policy”) outlines how researchers may report vulnerabilities, what is in scope, what is out of scope, and how Natty Hatty supports good-faith security research. vulnerabilities, what is in scope, what is out of scope, and how Natty Hatty will engage with good-faith researchers.

1. Purpose

The goals of this policy are to:

  • Encourage responsible reporting of security vulnerabilities

  • Protect youth-sports organizations and minors

  • Provide safe-harbor for legitimate researchers

  • Define the boundaries of acceptable testing

  • Support coordinated vulnerability disclosure best practices

Natty Hatty appreciates contributions from the security community.

2. Safe Harbor (Good-Faith Protection)

Natty Hatty commits that we will not pursue legal action against researchers who:

  • Engage in good-faith, non-destructive security testing

  • Follow all rules in this Policy

  • Avoid accessing private user data

  • Do not exploit a vulnerability after discovering it

  • Do not publicly disclose the vulnerability before Natty Hatty confirms remediation

  • Promptly delete any data inadvertently accessed

  • Do not engage in extortion, threats, or harm

Natty Hatty will interpret testing activities constructively, not punitively.

3. How to Report a Vulnerability

Email all vulnerability reports to:

security@nattyhatty.com

Subject Line: Security Vulnerability Report

Your report should include:

  • Detailed description of the issue

  • Steps to reproduce

  • Affected endpoint, URL, or component

  • Proof-of-concept (non-destructive)

  • Impact assessment

  • Your contact information for follow-up

Natty Hatty responds to all valid reports within 5 security-business days.

4. Eligibility for Recognition / Bounty Consideration

Natty Hatty may, at our discretion, offer:

  • Public acknowledgment

  • Swag

  • Gift cards

  • Monetary awards (if and when Natty Hatty’s formal bounty program launches)

To be eligible, the report must:

  • Be the first to identify the issue

  • Demonstrate real security impact

  • Be submitted with clear reproduction steps

  • Follow this Policy fully

Note: This policy establishes Responsible Disclosure. A formal cash bug bounty program may be introduced later.

5. In-Scope Targets

The following Natty Hatty systems are in scope:

5.1 Natty Hatty Web Business Center

  • Organization accounts

  • Staff accounts

  • Team management

  • Rosters, schedules, and events

  • Payments pages

  • Dashboard and analytics

  • Signature workflows

5.2 Natty Hatty Customer App (iOS & Android)

  • Authentication

  • Family/guardian accounts

  • Payments & registrations

  • Signature flows

  • Profile management

5.3 Signature / Document System

  • Signing endpoints

  • Audit trails

  • PDF generation

  • Access validation

5.4 API Endpoints

  • Public APIs

  • Mobile APIs

  • Real-time endpoints

5.5 Portal & Login Systems

  • Password reset flows

  • MFA flows

  • Session handling

Any vulnerabilities affecting the confidentiality, integrity, or availability of user data—especially minors’ data—are high priority.

6. Out-of-Scope Items

The following items are NOT in scope:

6.1 Social Engineering

  • Phishing Natty Hatty employees

  • Impersonation attacks

  • Vishing or baiting

6.2 Non-Security Bugs

  • UI/UX issues

  • Typos

  • Performance issues

  • Missing accessibility features

  • Minor account misconfigurations

6.3 Attacks that Risk User Safety

Strictly prohibited:

  • Testing targeting minors’ accounts

  • Attempting to access private roster, player, or guardian data

  • Attempting to intercept live signatures or private documents

6.4 Destructive or Disruptive Activities

Not allowed:

  • DDoS / traffic floods

  • Automated scanning at high volume

  • Brute force attacks

  • Spamming

  • Removing or altering data

  • Any action that degrades system performance

6.5 Use of Automated Tools

Excessive scanning tools (e.g., Nessus, Nikto, aggressive Burp Suite scans) are out of scope unless rate-limited and non-destructive.

7. Prohibited Actions (Strict)

Researchers must not:

  • Access, modify, or delete real user data

  • Create mass accounts or spam registrations

  • Attempt to charge real payment methods

  • View or alter minors’ information

  • Access live rosters, schedules, or teams

  • Download or modify signed documents

  • Run automated scripts that impact real events or payments

Natty Hatty enforces a strict zero-tolerance policy to protect minors and private data.

8. What Happens After You Submit a Report

Natty Hatty follows a standard disclosure lifecycle:

  • 1. Acknowledgment within 5 security-business days

  • 2. Assessment of severity and validity

  • 3. Replication of the issue internally

  • 4. Mitigation or patching

  • 5. Verification of fix

  • 6. Optional credit / acknowledgment (with your permission)

We strive to remediate valid high-impact vulnerabilities quickly, often within 72 hours.

9. Public Disclosure Rules

To protect users—especially minors—Natty Hatty requires:

  • No public disclosure until Natty Hatty confirms the issue is fixed

  • No sharing of reproduction details with third parties

  • No publication of exploits targeting minors’ data, payments, or authentication flows

Once resolved, Natty Hatty may mutually coordinate a public write-up.

10. Legal Safe Harbor Statement

As long as researchers follow this Policy:

  • Natty Hatty will not pursue legal action

  • Natty Hatty will not involve law enforcement (except in malicious cases)

  • Natty Hatty will treat research as authorized under CFAA (Computer Fraud and Abuse Act)

  • Natty Hatty will consider actions within scope as “permitted security research”

Malicious activity, data theft, extortion, or harm to minors voids safe harbor immediately.

11. Contact

For all vulnerability and security disclosures:

security@nattyhatty.com

For urgent or high-severity findings, include the subject line:

URGENT: SECURITY VULNERABILITY