Skip to content
CaveTown
Deutsch security.txt Privacy

Responsible disclosure

Security reporting

If you believe you found a vulnerability affecting CaveTown, please report it privately and give us a reasonable opportunity to investigate.

Quick guide

  • Report by email
  • Minimise accessed data
  • No destructive testing
  • No public disclosure before coordination

01

Contact

Send reports to support@cavetown.de with “Security report” in the subject. If sensitive material needs encrypted transport, request a dedicated channel before sending secrets, personal data or large evidence files.

02

Scope

Reports are welcome for systems operated under cavetown.de and kyouma.uk, and for configurations that directly affect their security. Third-party products, remote federated servers, Discord, client app stores and hosting-provider infrastructure should be reported to their respective operators unless CaveTown configuration is the cause.

03

What to include

  • the affected hostname or component without publishing private credentials,
  • a concise description of the impact,
  • reproducible steps using the smallest safe proof,
  • request and response details with tokens and personal data redacted, and
  • a way to contact you for follow-up.

04

Safe testing rules

Test only with your own account and data or with explicit prior permission. Stop once a vulnerability is demonstrated. Do not access, modify, retain or disclose another person’s data; do not establish persistence; and do not bypass invitations to create or control additional accounts.

05

Not permitted

  • denial-of-service, stress or resource-exhaustion testing,
  • automated high-volume scanning, credential stuffing or brute force,
  • social engineering, phishing or physical attacks,
  • malware, destructive payloads or modification of production data,
  • testing third-party accounts without their informed permission, and
  • public disclosure before a reasonable remediation discussion.

06

Response and recognition

We aim to acknowledge a well-formed report within seven days and provide a status update within 30 days, depending on severity and operator availability. CaveTown is a private, non-commercial project and does not operate a bug-bounty programme. Public credit can be discussed after remediation if the reporter requests it.

07

Privacy and good-faith reports

Report data is used to investigate, communicate about and remedy the issue, and is retained as needed for security documentation. Good-faith research that follows this policy will be handled cooperatively. This policy does not authorise violations of law or access beyond what is necessary to demonstrate the issue.

08

Current version

Updated 9 August 2026. The machine-readable contact is published at /.well-known/security.txt in the format defined by RFC 9116.

© 2026 CaveTown

Contact Accessibility Legal notice Privacy

Coordinated disclosure