Security Policy
Last updated: 23 August 2026
We welcome good-faith reports of security issues affecting the 1000AD Revived website, game APIs, Discord bot, or related infrastructure. This page describes how to report them and what to expect.
1. How to report
- Email noreply@1000ad-revived.com with subject line starting with
Security report - Or message staff via our community Discord (preferred during closed beta if email is slow to reach us)
Machine-readable contact details: /.well-known/security.txt.
2. What to include
- A clear description of the issue and its impact
- Steps to reproduce (URLs, request shape, screenshots if helpful)
- Whether you have a proof of concept, and how limited it is
- Your preferred contact for follow-up
3. Scope
In scope examples:
- Authentication or session flaws
- Unauthorized access to other players’ accounts or empire data
- Injection, XSS, CSRF, or privilege escalation on our domains
- Secrets exposure or insecure direct object references in APIs
Out of scope / lower priority:
- Game balance, cheating via intended mechanics, or UI polish
- Reports that only affect your own account without a security impact
- Social engineering of players (report abuse via Discord instead)
- Denial-of-service testing against production without prior approval
4. Safe harbor
If you research in good faith, avoid privacy violations and service disruption, and report promptly, we will not pursue legal action for that research. Do not access or modify data that is not yours beyond what is needed to demonstrate the issue.
5. Response
We aim to acknowledge reports within a few business days. There is no bug bounty program at this time; we may credit researchers who want acknowledgment once a fix ships.
Also see the Privacy Policy and Terms of Service.
