Responsible disclosure
Security reporting
If you believe you found a vulnerability affecting CaveTown, please report it privately and give us a reasonable opportunity to investigate.
01
Contact
Send reports to support@cavetown.de with “Security report” in the subject. If sensitive material needs encrypted transport, request a dedicated channel before sending secrets, personal data or large evidence files.
02
Scope
Reports are welcome for systems operated under cavetown.de and kyouma.uk, and for configurations that directly affect their security. Third-party products, remote federated servers, Discord, client app stores and hosting-provider infrastructure should be reported to their respective operators unless CaveTown configuration is the cause.
03
What to include
- the affected hostname or component without publishing private credentials,
- a concise description of the impact,
- reproducible steps using the smallest safe proof,
- request and response details with tokens and personal data redacted, and
- a way to contact you for follow-up.
04
Safe testing rules
Test only with your own account and data or with explicit prior permission. Stop once a vulnerability is demonstrated. Do not access, modify, retain or disclose another person’s data; do not establish persistence; and do not bypass invitations to create or control additional accounts.
05
Not permitted
- denial-of-service, stress or resource-exhaustion testing,
- automated high-volume scanning, credential stuffing or brute force,
- social engineering, phishing or physical attacks,
- malware, destructive payloads or modification of production data,
- testing third-party accounts without their informed permission, and
- public disclosure before a reasonable remediation discussion.
06
Response and recognition
We aim to acknowledge a well-formed report within seven days and provide a status update within 30 days, depending on severity and operator availability. CaveTown is a private, non-commercial project and does not operate a bug-bounty programme. Public credit can be discussed after remediation if the reporter requests it.
07
Privacy and good-faith reports
Report data is used to investigate, communicate about and remedy the issue, and is retained as needed for security documentation. Good-faith research that follows this policy will be handled cooperatively. This policy does not authorise violations of law or access beyond what is necessary to demonstrate the issue.
08
Current version
Updated 9 August 2026. The machine-readable contact is published at /.well-known/security.txt in the format defined by RFC 9116.