Security

Responsible disclosure and account safeguards

A clear route for reporting a vulnerability, plus an honest description of the security controls members can rely on.

No CoinPork KYC

CoinPork account creation, membership access, learning, games, support, platform rewards, and account withdrawal workflows do not ask for government ID or a selfie. An external provider may impose its own separate requirements if one is later enabled; those must be disclosed in the Provider Requirement Watch.

Report a vulnerability

Email a concise reproduction, affected URL, impact, and a safe contact method to the monitored address below. Do not include passwords, recovery phrases, private keys, payment data, government IDs, or another member's personal data.

support@coinpork.com

Safe testing boundary

Use only accounts and data you control. Avoid privacy invasion, social engineering, denial of service, destructive tests, automated volume, accessing funds, changing other accounts, or retaining data. Stop when a test could cause harm.

There is no promised bounty or guaranteed response time. Good-faith reports will be triaged through the normal security process.

Compromised-password screening

New and changed passwords are checked against the Have I Been Pwned Pwned Passwords service using a k-anonymous range query. Only the first five characters of a SHA-1 hash are sent; the password and complete hash are not transmitted.

Protected actions

Payout destination changes and account lockdown recovery require password re-entry, with MFA when enabled. Admin reward-rule, provider-requirement, and funding-budget changes also require password re-entry and create audit records. Passkeys remain available for phishing-resistant sign-in.

This disclosure route follows the location convention in RFC 9116. Security controls reduce risk; they do not make any internet service immune from compromise.