YLYour Legacy University
MethodPlatformProofPrivacy
Client loginBook a call ↗
HomePlatformPrivacy policyTerms & conditionsCookie noticeHow we use AISecurityCookie choicesClient login

Security & responsible disclosure

What we actually do, and what we do not claim.

Effective 9 August 2026Reviewed quarterly

This page describes controls that are in place today. Where something is not in place, it says so. If you have found a weakness in any of our systems, section 01 tells you how to reach us.

At a glance
01Report a vulnerability to securityyourlegacyuni@gmail.com. We reply within five business days.
02Members can export or delete their own data without asking us.
03We are not SOC 2 certified and we do not say we are.

Security contents

  1. 01Reporting a Vulnerability
  2. 02Safe Harbour & Scope
  3. 03Data in Transit
  4. 04Access & Authorisation
  5. 05Your Data, Your Control
  6. 06How AI Handles Your Information
  7. 07Who Else Processes Data
  8. 08What We Do Not Claim
  9. 09Contact
01

Reporting a Vulnerability

If you believe you have found a security weakness in any Your Legacy University system, we want to hear from you before anyone else does.

Security contactsecurityyourlegacyuni@gmail.comMonitored during business hours, Ireland (IST/GMT).

We will acknowledge your report within five business days and tell you whether we can reproduce it. We will keep you updated while we fix it, and we will credit you when it is resolved if you would like us to.

It helps enormously if your report includes the affected URL or endpoint, the steps to reproduce, what you were able to access or change, and any account you used. A short screen recording is worth a page of description.

These systems are in scope:

  • www.yourlegacyco.com — this marketing site
  • app.yourlegacyco.com — the coaching platform, where member data lives
  • builder.yourlegacyco.com — Legacy Builder
  • growth.yourlegacyco.com — Growth Studio
02

Safe Harbour & Scope

If you make a good-faith effort to follow this policy while researching, we will treat your research as authorised. We will not pursue legal action against you, and if a third party does, we will make clear that you were acting within this policy.

Good faith means: stop as soon as you have proved the issue, use only accounts you own or test accounts you created, and give us reasonable time to fix it before telling anyone else.

Please do not do any of the following, because they cause harm rather than demonstrate it:

  • Access, modify or delete data belonging to another person. Prove the issue with your own account.
  • Run denial-of-service tests, load tests, or automated scanners that generate high volumes of traffic.
  • Use social engineering, phishing, or physical attempts against our staff or suppliers.
  • Publish details before we have had a chance to fix the issue.

Some things are outside scope because they are not weaknesses we can act on: missing security headers with no demonstrated impact, results from automated scanners without a working proof of concept, reports about software we do not control, and issues that require an attacker to already have physical access to a person's unlocked device.

We do not currently run a paid bug bounty. We would rather tell you that plainly than imply a reward that does not exist.

03

Data in Transit

Every one of our sites is served over HTTPS only. All four send HTTP Strict Transport Security, so a browser that has visited once will refuse to connect over plain HTTP afterwards, even if a link tries to.

The coaching platform and Legacy Builder both enforce a Content Security Policy that names, explicitly, every external origin allowed to run a script, load a font, open a connection or embed a frame. Anything not on that list is blocked by the browser. This is the control that limits the damage of an injected script.

All four sites also send X-Content-Type-Options: nosniff, a referrer policy that withholds the full path from other sites, and a permissions policy that switches off camera, microphone and location by default.

04

Access & Authorisation

The browser is a suggestion. The server is the authority. Hiding a button in the interface is presentation, not protection, because anyone can type a URL. So every request that returns or changes information belonging to a person is checked on the server, against the person making the request.

In practice that means a query for your messages is constrained by who you are, rather than by an identifier we accepted from your browser. Asking for someone else's record by changing a number in a URL returns nothing.

Access levels are declared in one place and read by both the interface and the API, so the button you can see and the answer the server gives cannot disagree. Sensitive rooms and financial data are restricted to owner accounts, and no invitation can create one.

Invitation links are stored only as a SHA-256 hash, expire, are single-use by default, can be bound to one email address, and can be revoked instantly. Reading our database would not let anyone mint access.

Nothing about price, plan or entitlement is decided in your browser.

05

Your Data, Your Control

These are working features in the coaching platform, not promises to handle a request by hand:

  • Export everything we hold about you. A subject access request you can run yourself.
  • Delete your account. Erasure is scheduled and carried out; you do not need to email anyone.
  • Object to marketing. Objection is enforced at the point of sending, not merely recorded as a preference.
  • Opt out without an account. A public endpoint honours the request whether or not you are a member.

Members never receive each other's email addresses. Directory and community screens identify people by a one-way hash of their address, so a member's photo can be shown without publishing how to contact them.

06

How AI Handles Your Information

Several parts of our products use AI models: the coaching assistant, the platform guide, and the generation lane inside Legacy Builder. It is worth being precise about what that means for your information.

What is sent. When you use one of these features, the text of your request goes to a model provider so it can answer. In Legacy Builder that is the brief you write about your business. Where a screenshot or recording is supplied as a visual reference, that file goes to the build engine.

What is not sent. Your password is never sent to a model, because we never hold it in a readable form. Payment card details are never sent, because they go directly to our payment processor and we never see the full number.

What we ask of it. Generated pages are instructed never to invent a credential, testimonial, figure or claim you did not supply. That rule is enforced in the prompt and checked afterwards, because a site that invents a statistic about your business is a liability we are handing you.

Please do not paste passwords, card numbers, or a client's confidential information into any AI feature. Nothing about your use of these tools requires it.
07

Who Else Processes Data

We do not run our own data centres. Delivering these products means a small number of suppliers necessarily process information on our behalf — hosting, database, payments, transactional email and AI model providers among them.

The categories, and the safeguards that apply when information leaves your region, are set out in our Privacy Policy, section 09, and international transfers in section 11.

We are preparing a named, per-supplier list to publish here, along with the purpose each one serves. We would rather publish that once it is complete and accurate than publish a partial one now.

08

What We Do Not Claim

Security pages tend to imply more than they say. So, plainly:

  • We are not SOC 2 certified. We have not undergone a SOC 2 Type I or Type II audit.
  • We are not ISO 27001 certified.
  • We do not commission annual third-party penetration tests. Our testing is performed internally.
  • We do not operate a paid bug bounty programme.

These are the things a much larger company would list, and we will not borrow their credibility by staying vague. What we have instead is a small, closely-held system where the controls described above are real, tested, and written down.

09

Contact

For a security issue, use the address in section 01 — it reaches us fastest.

Security reports

securityyourlegacyuni@gmail.com

Acknowledged within five business days

Privacy requests and everything else

See the Privacy Policy

Machine-readable contact details are published at /.well-known/security.txt, following RFC 9116.

YLYour Legacy University

Owned websites, private client platforms and operating systems for established coaches, consultants and founders.

HomePrivacy policyTerms & conditionsCookie noticeHow we use AICookie choicesContact

© 2026 Build Your Legacy LLC. Guidance on this website is informational and does not replace the controlling agreement.