Skip to content
C Chatkode

Security reports

Responsible disclosure

If you believe you have found a security issue in Chatkode, please tell us privately so we can investigate and fix it. Good-faith researchers who follow this process help everyone who relies on private messaging.

How to report

  1. Email support@chatkode.com with a clear description, steps to reproduce, and impact.
  2. Do not access other people’s accounts or data beyond what is needed to demonstrate the issue.
  3. Give us a reasonable time to investigate before public discussion.

Also see security.txt.

What we ask

  • No social engineering of Chatkode staff or users.
  • No denial-of-service testing that harms availability for others.
  • No spam or automated mass scanning that overwhelms the service.

We do not currently operate a paid bug bounty. We still appreciate clear, good-faith reports and will respond as we are able.

Safe harbor intent

If you make a good-faith effort to follow this process and avoid privacy harm, we intend to treat the report as authorized security research for Chatkode systems you tested — not as a malicious attack. This is not legal advice and does not cover illegal activity or third-party systems.

Ready to Match?

Random chat that’s private — no phone number. Match, Skip, encrypted 1:1. Claim your account in 24 hours.

Start Random Chat

Frequently asked questions

Is there a bug bounty?

Not at this time. We still welcome responsible reports to support@chatkode.com.

How quickly will you reply?

We aim to acknowledge reports as soon as practical. Complex issues may take longer to investigate.

Where is the security overview?

See security.html for product security practices in plain language.