Responsible Disclosure

Help us address security issues safely.

This policy covers Coflnet-operated services and systems. Third-party platforms and data are outside its scope unless you have their separate authorization.

Good-faith conditions

Research is permitted under our Terms only if you:

  • use only your own accounts or systems you are authorized to test;
  • minimize testing and stop if you encounter third-party or personal data;
  • do not access, copy, retain, disclose or exfiltrate data beyond what is strictly necessary to demonstrate the issue;
  • do not disrupt services, use denial-of-service or social-engineering techniques, establish persistence, or impair other users;
  • do not exploit a vulnerability to obtain or retain credits, access, items or other benefits; and
  • report privately, give us a reasonable opportunity to investigate and fix the issue, and comply with applicable law.

Report an issue

Email [email protected] or use our contact form. Include the affected service, reproduction steps, impact and relevant times, but do not send live secrets or unnecessary personal data.

Safe harbour and rewards

If you follow this policy, Coflnet will not treat the research or report as misuse under its Terms or pursue contractual claims based solely on that compliant activity. This policy cannot authorize conduct affecting third parties, bind public authorities or waive mandatory rights.

Reporting does not guarantee a bounty or other reward. Any reward is voluntary unless agreed separately in writing.