Security Philosophy & Responsible Disclosure
CopyCharacter takes software integrity, web application security, and visitor data protection seriously. We recognize the invaluable role that independent security researchers play in identifying vulnerabilities.
If you believe you have discovered a security flaw or technical vulnerability affecting our platform, we encourage you to disclose it to us responsibly so that we may investigate and remediate the issue promptly before public exposure.
In-Scope & Out-of-Scope Targets
✅ In-Scope Targets
- Production domain:
https://copycharacter.com/* - Routing engine, HTTP parameter processing, and view rendering.
- Cross-Site Scripting (XSS) in character search and encoding converters.
- Cross-Site Request Forgery (CSRF) on contact and error forms.
- Remote code execution or arbitrary file inclusion vulnerabilities.
❌ Strictly Out-of-Scope
- Denial of Service (DoS or DDoS) attacks against web servers or CDN edge nodes.
- Automated volume scanning, brute-forcing, or form spamming.
- Social engineering, phishing, or physical intrusion attempts.
- Vulnerabilities in third-party hosted services (e.g. Cloudflare, Google AdSense) that do not directly affect our application code.
Safe Harbor & Prohibited Testing Activities
To qualify for safe harbor and avoid legal action, researchers must conduct testing strictly within these parameters:
- Do not compromise the availability, performance, or integrity of services for other visitors.
- Do not access, modify, or exfiltrate another user's browser storage or contact submissions.
- Give our development team reasonable time (minimum 30 days) to deploy a fix before publishing any technical vulnerability write-up or proof of concept.
How to Submit a Vulnerability Report
Please email your report directly to [email protected] or use our structured contact routing portal:
Submit a Security Report
Direct your vulnerability report to our dedicated security inbox with rapid triage.
Include a clear vulnerability description, steps to reproduce with HTTP request/response transcripts or minimal curl commands, and your assessment of the vulnerability's impact.
Acknowledgment & Patch Deployment SLA
- Initial Acknowledgment: Within 24 to 48 hours of receipt.
- Triage & Assessment: Within 5 business days.
- Patch Deployment: Critical severity issues are patched with emergency priority; moderate issues are deployed within standard release cycles.
RFC 9116 security.txt Endpoint
In accordance with the RFC 9116 specification for web security disclosures, CopyCharacter maintains a machine-readable security policy file at: