Security

Responsible Disclosure Policy

Help us keep Koppa and all related platforms secure.

At Koppa, we take the security of our platforms seriously. This policy covers everything we run:

(including the subdomains and APIs that serve them)

If you discover a vulnerability or potential security issue, we’d like to hear from you — so we can investigate and address it as quickly as possible.


📬 Contact

You can report security issues directly to:


🎯 Scope

This policy applies to all public-facing services and domains operated by Koppa, including the sites and apps listed above. Platforms we no longer operate — such as our retired whitelabel domains — are out of scope. Issues outside this scope may not be prioritized unless they pose a significant risk.


✅ We Appreciate

  • Clear, concise vulnerability reports.
  • Reports that respect our users’ privacy and do not access unnecessary data.
  • Use of test accounts where possible.
  • Time to fix the issue before public disclosure (a reasonable timeframe, typically 30 days).

🚫 Please Avoid

  • DDoS attacks or brute force attempts.
  • Social engineering against employees or partners.
  • Spamming, phishing, or compromising systems you do not own.
  • Physical security testing of Koppa facilities or offices.

⚖️ Safe Harbor

We will not pursue legal action against researchers who:

  • Act in good faith.
  • Follow the rules in this policy.
  • Report vulnerabilities privately and responsibly.

🎉 Recognition

We maintain a Hall of Fame page for researchers who help keep our platforms secure:
👉 Koppa Security Hall of Fame

If you’d like recognition, please let us know — we’re happy to credit your contributions publicly (or keep them anonymous if preferred).


🔐 Data & Privacy

All vulnerability data will be handled confidentially in accordance with our Privacy Policy. You can read more about how we process user data and security-related information there.