Security policy.
Loops Coffee + Yarn is a small independent business. If you find a security issue on our site, this page explains how to report it and what to expect in return.
1. Scope
This policy applies to the Loops Coffee + Yarn website and any subdomains we operate:
- loopsclt.com and www.loopsclt.com
- Future subdomains we publish under loopsclt.com
The following are out of scope and should not be tested:
- Third-party services embedded on our site, such as Kit (formerly ConvertKit) email forms, Cloudflare, and our hosting infrastructure. Report issues with these services directly to the provider.
- Denial-of-service or volumetric testing
- Social engineering of staff, vendors, or customers
- Physical access attempts to any Loops location
- Automated vulnerability scanners that do not verify their findings
2. How to report
If you find a vulnerability, please email security@loopsclt.com with the subject line starting with Security.
Include what you have:
- A clear description of the issue
- Steps to reproduce, including any URLs or requests involved
- What you think the impact is
- A suggested fix, if you have one in mind
We will acknowledge your report within 5 business days. If the issue is confirmed and in scope, we will share a target timeline for remediation and keep you updated as we work.
3. Safe harbor
We will not pursue legal action against security researchers who:
- Act in good faith and follow this policy
- Avoid privacy violations, data destruction, and service disruption
- Give us a reasonable window, typically 90 days, to fix an issue before public disclosure
- Comply with applicable laws during their testing
If you are unsure whether something is in scope or how to proceed, email us first. We would rather answer a question than receive a surprise.
4. No bug bounty
Loops does not currently operate a paid bug bounty program. We appreciate responsible disclosure and will credit researchers who ask to be named, but we cannot offer cash rewards or swag at this time.
5. Contact
Loops Coffee + Yarn
Email: security@loopsclt.com
Machine-readable: /.well-known/security.txt