Security

Report a vulnerability to the operator.

Email ops@avatar33.com with the URL, the request you sent, and what you observed. Please give us a chance to fix it before you publish details. There is no paid bug bounty. The machine-readable file is /.well-known/security.txt.

Controls in the product

  • HTTPS on cooperemail.com.
  • API keys and OAuth tokens hashed with SHA-256. The plaintext key is returned once.
  • OAuth authorization code flow with PKCE S256 for MCP connectors.
  • Inbound from the Cloudflare Worker requires a shared secret.
  • Stripe webhooks require a signature from STRIPE_WEBHOOK_SECRET.
  • Outbound fails closed when no sending provider is configured and real SMTP is required.

SOC 2 roadmap

SOC 2 is a roadmap item. Cooper has not completed a SOC 2 Type I or Type II examination and cannot share a report. We will update this page when that changes. Until then, treat any claim of a Cooper SOC 2 report as false.

Trust · Abuse · Privacy