Security
Report a vulnerability to the operator.
Email ops@avatar33.com with the URL, the request you sent, and what you observed. Please give us a chance to fix it before you publish details. There is no paid bug bounty. The machine-readable file is /.well-known/security.txt.
Controls in the product
- HTTPS on cooperemail.com.
- API keys and OAuth tokens hashed with SHA-256. The plaintext key is returned once.
- OAuth authorization code flow with PKCE S256 for MCP connectors.
- Inbound from the Cloudflare Worker requires a shared secret.
- Stripe webhooks require a signature from STRIPE_WEBHOOK_SECRET.
- Outbound fails closed when no sending provider is configured and real SMTP is required.
SOC 2 roadmap
SOC 2 is a roadmap item. Cooper has not completed a SOC 2 Type I or Type II examination and cannot share a report. We will update this page when that changes. Until then, treat any claim of a Cooper SOC 2 report as false.