LEGAL
Security & Responsible Disclosure
Version 2026-09-28-v1 · effective 28/09/2026
Security & Responsible Disclosure
Status: Draft for review — not yet published.
1. Reporting a security issue
If you believe you have found a security vulnerability affecting CheckOpp, report it privately to:
office@koretskiy.rs
Include enough detail to reproduce the issue, but do not include unnecessary personal data or third-party confidential information.
2. Do not access other users' data
Security research must not involve accessing another user's Case or account without authorization, downloading/retaining third-party files, changing/deleting data, disrupting service availability, social engineering, credential theft, malware, or high-volume scanning that materially degrades the service.
3. Minimal proof
Use the minimum activity necessary to demonstrate a suspected vulnerability. If a test could affect real users or data, stop and contact CheckOpp before continuing.
4. Confidential reporting
Do not publicly disclose an unremediated vulnerability or sensitive technical details before CheckOpp has had a reasonable opportunity to investigate and address the issue.
5. What CheckOpp may request
We may ask for affected URL/screen, reproduction steps, timestamps, browser/device information, redacted screenshots and a technical explanation of impact.
6. Good-faith review
CheckOpp does not currently operate a formal bug-bounty or legal safe-harbor program. This policy is not authorization to test systems beyond the minimum activity necessary to report a suspected issue. Researchers should contact CheckOpp before any test that could access real user data, affect availability or go beyond ordinary public functionality.
7. Security incidents
CheckOpp may preserve logs and restrict access where necessary to investigate suspected unauthorized access, abuse or a material security incident.
8. No bug bounty promise
Unless separately announced, this policy does not create a right to payment, reward or compensation for vulnerability reports.
Published version: 2026-09-28-v1