What Eight Security Reports Taught Us in One Week ๐ก๏ธ
We launched a Vulnerability Disclosure Program (VDP) for 4leggedIT with a simple goal: give people a safe, official way to tell us when something is wrong. Security issues, usability problems, workflow friction, things we simply overlooked while building.
Within less than a week, more than eight reports came in.
The First Reaction Isn't Always the Right One
Eight reports in a week can feel like a lot, especially when several land close together. It is easy to read that number as "look how much is broken."
It is also easy to get defensive about it. We built and tested every one of these sites ourselves. Discovering something we missed can feel less like useful information and more like a critique of the work.
That reaction is natural. It is also the wrong one to act on.
Reports Aren't Criticism. They're Information We Didn't Have.
A report is someone spending their own time looking at our work from an angle we didn't. Every one of them is an opportunity to see a site the way a real visitor, or a real attacker, actually sees it, not the way we assumed they would.
Not every report is the same weight. Some are simple oversights, easy to fix in minutes. Others expose something deeper in the workflow, the accessibility, or the process that produced the page in the first place. Both are worth exactly as much of our attention, because both are true statements about the current state of the site.
One report we received wasn't a vulnerability at all. It flagged a portal that logs a user in immediately after registration, no email verification step. We looked closely and concluded it wasn't a security gap for that particular system, but the reporter was doing exactly what a good-faith researcher should do, and had already been told recognition would follow. So it earned a different kind of credit: a "Security Contributions" entry alongside our confirmed-vulnerability Hall of Fame, for reports that are valuable without being an actual vuln. Not every useful report fits neatly into one bucket, and our recognition process needed to grow to reflect that.
The Goal Was Never Zero Mistakes
No amount of testing before launch catches everything. That was never realistically the goal.
The actual goal is a process that learns from what gets found, every time, without needing to be re-litigated from scratch on each report:
Build โ Test โ Launch โ Listen โ Learn โ Improve โ Share
Listening is the step that's easy to skip when a report first lands and the instinct is to explain, justify, or minimize. The reports that matter most are the ones that make it past that instinct into an actual fix.
One Fix, the Whole Fleet
Here's where the VDP connects to something we already believe in: template.4leggedit.com exists so that an improvement made for one rescue becomes an improvement for every rescue on the platform.
A recent batch of reports pointed out that email authentication (the settings that stop someone from spoofing a "from" address on one of our domains) was missing or incomplete across several of the sites we manage. That is not a one-site problem. It is a shared-infrastructure problem, so it got a shared-infrastructure fix: every domain we control got audited and hardened in the same pass, not just the ones named in the original reports, and the hardening steps got written down as a reusable playbook for the next domain that joins the fleet.
That is the difference between patching a symptom and fixing the actual gap. A discovery on one project becomes protection for every project built the same way.
We wrote more about how this works in Built Once, Shared With Every Rescue.
Recognition, Not Payment
We don't offer monetary bug bounties. What we do offer is real, public recognition: the 4leggedIT Security Hall of Fame, where confirmed findings and valuable good-faith reports both get credited by name (or handle, or anonymously, whichever the reporter prefers).
That distinction matters to us. The people reporting are volunteering their time and skill to make something safer for rescues, volunteers, and adopters who never asked to think about DNS records or row-level security. The least we can do is say so publicly and mean it.
Sharing It Beyond the Fleet
Everything this process teaches us doesn't have to stay inside 4leggedIT. When a lesson or a fix is useful beyond our own client sites, whether that's a hardening playbook, a governance rule, or just a better way to reply to a report, there's no reason to keep it proprietary. Template.4leggedit.com is open. If a rescue, a developer, or another small org can use what we learned, we would rather they didn't have to learn it the hard way too.
Where We Landed
What started as "look at everything people are finding" turned into "look at everything people are helping us improve." Eight reports in a week wasn't a bad launch. It was the VDP doing exactly what it was built to do.
Build. Test. Launch. Listen. Learn. Improve. Share. Then do it again.
Ready to simplify your rescue's website?
Learn how 4leggedIT can help your organization thrive with technology that works for you. No lock-in. No pressure. Just practical support.
Get Started