LEGAL

Security & Responsible Disclosure

Version 2026-09-28-v1 · effective 28/09/2026

Security & Responsible Disclosure Status: Draft for review — not yet published. 1. Reporting a security issue If you believe you have found a security vulnerability affecting CheckOpp, report it privately to: office@koretskiy.rs Include enough detail to reproduce the issue, but do not include unnecessary personal data or third-party confidential information. 2. Do not access other users' data Security research must not involve accessing another user's Case or account without authorization, downloading/retaining third-party files, changing/deleting data, disrupting service availability, social engineering, credential theft, malware, or high-volume scanning that materially degrades the service. 3. Minimal proof Use the minimum activity necessary to demonstrate a suspected vulnerability. If a test could affect real users or data, stop and contact CheckOpp before continuing. 4. Confidential reporting Do not publicly disclose an unremediated vulnerability or sensitive technical details before CheckOpp has had a reasonable opportunity to investigate and address the issue. 5. What CheckOpp may request We may ask for affected URL/screen, reproduction steps, timestamps, browser/device information, redacted screenshots and a technical explanation of impact. 6. Good-faith review CheckOpp does not currently operate a formal bug-bounty or legal safe-harbor program. This policy is not authorization to test systems beyond the minimum activity necessary to report a suspected issue. Researchers should contact CheckOpp before any test that could access real user data, affect availability or go beyond ordinary public functionality. 7. Security incidents CheckOpp may preserve logs and restrict access where necessary to investigate suspected unauthorized access, abuse or a material security incident. 8. No bug bounty promise Unless separately announced, this policy does not create a right to payment, reward or compensation for vulnerability reports.

Published version: 2026-09-28-v1

← All legal documents

Methodology © Oleksandr KoretskiyMethodologyGlossary