Security notice
Taverna Royale takes security reports seriously to protect account, payment, online match, chat, Firebase, Photon and store integrations. The primary channel for vulnerability reports is security@tavernaroyale.com.
Do not harm player data
Tests that harm a real player's account, personal data, purchase records, chat content, match outcomes, or service availability are considered unauthorized. If in doubt, submit a report first and wait for permission.
| In scope | Account takeover risk, unauthorized data access, payment/receipt manipulation, Cloud Functions authorization errors, Firestore/RTDB rule gaps, App Check/Auth bypass, server-authoritative match integrity, chat moderation bypass, and sensitive information leaks. |
|---|---|
| Out of scope | Spam, social engineering, physical attacks, DDoS, high-volume scanning, attacks on third-party accounts, low-impact reports based on public information, and tests targeting a user's own device. |
| Reward program | There is currently no open bug bounty or cash reward program. Submitting a report does not create a reward, fee, or employment relationship. |
Safe testing rules
- Do not read/modify data outside your own account or an explicitly permitted test account.
- Do not manipulate match outcome, ELO, wallet, purchase or leaderboard values in production.
- Do not exfiltrate data; a minimal screenshot, request summary, and timestamp are sufficient as evidence.
- Do not run automated scanning, brute force, load testing, or DoS attempts that could cause a service outage.
Expected conduct
- Give us a reasonable time to fix the issue before any public disclosure.
- For critical reports affecting player safety, mark the subject "Critical Security".
- If you accidentally see personal data, do not retain or share it, and state only the minimum information in the report.
Report format
- Short title and impact: account, payment, data, match integrity, chat, or infrastructure.
- Affected platform: iOS, Android, web, Firebase, Photon, or a store integration.
- Reproduction steps, timestamp, test account, and a request/response summary if possible.
- Expected behavior, observed behavior, and a suggested safe fix.
- An email address where we can reach you.
For non-security support requests, use support@tavernaroyale.com; for payments, billing@tavernaroyale.com; for legal notices, legal@tavernaroyale.com.
Abuse and account security
Player-safety reports such as account takeover, payment fraud, cheating, harassment, or chat safety may also be evaluated under security scope. However, for real-world physical emergencies, contact your local competent authorities.
Short summary
Report security vulnerabilities to security@tavernaroyale.com. Do not access, modify, retain, or disclose player data. Do not disrupt the service, manipulate purchases or match outcomes, and do not test on accounts that are not yours.
