Security
Responsible Disclosure Policy
At Koppa, we take the security of our platforms seriously. This policy covers everything we run:
- gokoppa.com — our company website
- koppafootball.com — Koppa Football, our score prediction game
- koppacycling.com — Koppa Cycling, our stage prediction game
- koppa.app and getkoppa.com — our app and campaign sites
- The Koppa apps for iOS and Android
(including the subdomains and APIs that serve them)
If you discover a vulnerability or potential security issue, we’d like to hear from you — so we can investigate and address it as quickly as possible.
📬 Contact
You can report security issues directly to:
- Email: security@gokoppa.com
- PGP Key: gokoppa.com/security/pgp-key.txt (for encrypted reports)
- Preferred Languages: English, Dutch
🎯 Scope
This policy applies to all public-facing services and domains operated by Koppa, including the sites and apps listed above. Platforms we no longer operate — such as our retired whitelabel domains — are out of scope. Issues outside this scope may not be prioritized unless they pose a significant risk.
✅ We Appreciate
- Clear, concise vulnerability reports.
- Reports that respect our users’ privacy and do not access unnecessary data.
- Use of test accounts where possible.
- Time to fix the issue before public disclosure (a reasonable timeframe, typically 30 days).
🚫 Please Avoid
- DDoS attacks or brute force attempts.
- Social engineering against employees or partners.
- Spamming, phishing, or compromising systems you do not own.
- Physical security testing of Koppa facilities or offices.
⚖️ Safe Harbor
We will not pursue legal action against researchers who:
- Act in good faith.
- Follow the rules in this policy.
- Report vulnerabilities privately and responsibly.
🎉 Recognition
We maintain a Hall of Fame page for researchers who help keep our platforms secure:
👉 Koppa Security Hall of Fame
If you’d like recognition, please let us know — we’re happy to credit your contributions publicly (or keep them anonymous if preferred).
🔐 Data & Privacy
All vulnerability data will be handled confidentially in accordance with our Privacy Policy. You can read more about how we process user data and security-related information there.