Security & Responsible Disclosure
Report security issues responsibly. We prioritize account integrity, payout safety, reward accounting and provider callback security.
How to report
- Email support@cryptochoco.com with a clear subject such as “Security report”.
- Describe affected URL/component, preconditions, reproducible steps, observed impact and suggested remediation if known.
- Use test accounts and the minimum data necessary. Do not access unrelated user data, attempt social engineering or perform denial-of-service testing.
- Allow reasonable time for investigation and remediation before public disclosure.
Priority scope
- Authentication, sessions and account recovery.
- Withdrawal / FaucetPay flows and payout reconciliation.
- RewardService, balance integrity and idempotency.
- Paid Ads Verified Active View and advertiser accounting.
- Provider callbacks, signatures, postback replay or chargeback handling.
- Choco Draw fairness, entry integrity and winner crediting.
Security research rewards
CryptoChoco does not currently operate a public bug bounty program. Monetary rewards are not guaranteed for unsolicited vulnerability reports. Responsible reports are reviewed based on demonstrated impact and may still result in remediation, but submitting a report does not create a payment obligation.
Safe-harbor intent
Good-faith research that stays within the boundaries above is welcomed. We ask researchers to avoid privacy violations, data destruction, service disruption and financial abuse. CryptoChoco will evaluate reports based on demonstrated impact rather than scanner output alone.