Reporting
Send reports to security@coopsphere.org with enough detail to reproduce the issue: affected URL or feature, steps, impact and any supporting evidence. We acknowledge reports and will keep the reporter informed of progress.
Safe harbour
We will not pursue action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.
Out of scope
- Denial-of-service, volumetric or load testing.
- Social engineering of staff, customers or members.
- Physical attacks, spam, or automated scanner output without a demonstrated impact.
- Accessing, modifying or exfiltrating data belonging to other organizations or members.
Our commitment
We triage reports by severity, remediate confirmed issues, and credit reporters where they wish to be acknowledged. We do not currently operate a paid bug-bounty programme.
This document describes how Coopsphere is operated by ASH Global Network Ltd. It is not legal advice and does not assert any third-party certification or audit outcome. For questions, contact support@coopsphere.org.