What to report
Describe the affected page or system, reproducible steps, potential impact, discovery time and a secure contact method. Do not include real user data, credentials or sensitive material beyond what is necessary to demonstrate the issue in an initial report.
Responsible testing boundary
Use non-destructive validation only within systems you are authorized to access. Do not perform denial of service, social engineering, deletion or alteration, persistence, bulk data access, or activity that affects real users or third-party systems.
Response process
POOK triages reports according to reproducibility, scope and urgency, then coordinates confirmation and remediation. Response timing depends on complexity. Please avoid publishing exploitable technical detail before remediation and disclosure coordination are complete.
Current scope
This process currently covers the public POOK website and systems explicitly confirmed by POOK. Issues in third-party platforms and suppliers should also follow the provider's official disclosure channel.
Security contact
Use the website contact route and select the security topic. Include a secure way to respond. For urgent issues, state the affected scope and severity clearly in the subject and summary.
