CryptoChoco logo CryptoChoco
Security trust

Security & Responsible Disclosure

Report security issues responsibly. We prioritize account integrity, payout safety, reward accounting and provider callback security.

security.txt
Published
View RFC 9116 file →
Report channel
support@cryptochoco.com
Include reproduction steps and impact. Do not include secrets you do not need to disclose.
DNSSEC
UNKNOWN
DNSSEC is controlled at the DNS/registrar layer, not by the application release.

How to report

  1. Email support@cryptochoco.com with a clear subject such as “Security report”.
  2. Describe affected URL/component, preconditions, reproducible steps, observed impact and suggested remediation if known.
  3. Use test accounts and the minimum data necessary. Do not access unrelated user data, attempt social engineering or perform denial-of-service testing.
  4. Allow reasonable time for investigation and remediation before public disclosure.

Priority scope

  • Authentication, sessions and account recovery.
  • Withdrawal / FaucetPay flows and payout reconciliation.
  • RewardService, balance integrity and idempotency.
  • Paid Ads Verified Active View and advertiser accounting.
  • Provider callbacks, signatures, postback replay or chargeback handling.
  • Choco Draw fairness, entry integrity and winner crediting.

Safe-harbor intent

Good-faith research that stays within the boundaries above is welcomed. We ask researchers to avoid privacy violations, data destruction, service disruption and financial abuse. CryptoChoco will evaluate reports based on demonstrated impact rather than scanner output alone.