Security and vulnerability disclosure
If you have found a security problem in spiced.gg, we want to hear about it.
Reporting
Use the contact form. Include enough to reproduce the issue: the URL or endpoint, the steps, and what you saw. If a proof of concept is easier than a description, send that.
What we ask
- Report it before disclosing it publicly, and give us a chance to fix it.
- Use your own account and your own test games. Do not access, change or delete data belonging to anyone else.
- Do not run denial of service tests, send spam, or use social engineering against our staff or our developers.
- Stop as soon as you have confirmed the issue. You do not need to prove how far it goes.
What we will do
- Acknowledge your report.
- Tell you whether we consider it a vulnerability, and why if we do not.
- Keep you updated while we fix it, and tell you when it is fixed.
- Credit you if you would like to be credited, and not if you would not.
We do not currently run a paid bounty programme.
Scope
Anything on spiced.gg and the APIs behind it. Games are third-party code running in their own sandboxed origin: a bug in one game is a matter for its developer, but a way out of that sandbox, or from one game to another game’s data, is very much ours and is the class of report we are most interested in.
Findings from automated scanners without a demonstrated impact are usually not vulnerabilities, and neither are missing headers on responses that carry nothing.
Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will say so if anybody asks us. If you are unsure whether something is in scope, ask first through the contact form.
Machine-readable version: /.well-known/security.txt