TopoTopic Legal
How TopoTopic protects data, and how to report vulnerabilities responsibly.
Last updated 2026-08-25.
TopoTopic stores knowledge people care about, so security is part of the product, not an afterthought. Our practices include:
We do not currently claim certification under ISO 27001, SOC 2, or similar frameworks, and we will not claim one until an audit has actually been completed. If a personal data breach occurs that is likely to result in a risk to affected users, we notify the competent supervisory authority and, where required, affected users, in line with Articles 33 and 34 GDPR, as described in the Privacy Policy.
If you believe you have found a security vulnerability in TopoTopic, we want to hear about it. Send a report to support@topotopic.comwith the subject "Security Report". A machine-readable pointer to this policy is published at /.well-known/security.txt.
A useful report includes:
We aim to acknowledge reports within 5 business days. We will keep you informed of our progress, and we are happy to credit reporters who wish to be named once an issue is fixed. We do not currently run a paid bug bounty program.
We will not pursue action against good-faith security research that stays within these rules:
Testing that follows these rules is authorized use for the purposes of our Acceptable Use Policy. Out of scope: vulnerabilities in third-party services we use (report those to the provider), findings that only work with physical access to a victim's device, and reports generated by automated tools without a demonstrated impact.
We triage reports, reproduce the issue, and fix confirmed vulnerabilities with a priority that matches their impact. Where a vulnerability affected personal data, we assess our notification duties under the GDPR and follow them.
We treat report contents confidentially, and we ask the same of reporters until a coordinated disclosure. Personal data you include in a report is processed to handle the report, as described in the Privacy Policy.
Last updated 2026-08-25.
We use cookies to keep you signed in. Optional analytics are off unless you allow them. We do not sell personal information or share it for cross-context behavioral advertising. Privacy policy • Cookie policy