Report a Security Incident
CookPDF · 7/16/2026
How to submit a report
Email legal@cookpdf.io with the subject “Security Report.” State the affected URL or component, the test environment, the steps to reproduce, the expected impact, and the minimum necessary technical evidence.
Responsible reporting principles
- Do not access, modify, or download others' data.
- Do not disrupt, degrade the service, or perform destructive testing.
- Do not use social engineering, spam, or attacks on third-party providers.
- Do not disclose sensitive information before CookPDF has a reasonable time to investigate.
Data you should not send
Do not send passwords, secret keys, payment data, other users' documents, or exploit code that could cause harm. If your evidence contains sensitive information, describe it first so we can agree on a safer way to provide it.
Scope of response
CookPDF reviews reports based on reproducibility, impact, and service scope. This page does not create any commitment regarding response time, rewards, or a bug bounty program.
Account or privacy incidents
If the issue only concerns a personal account, please contact support@cookpdf.io. Privacy requests can be sent to legal@cookpdf.io.