Core:Vulnerability

From Tootsville Wiki-Wiki
Jump to: navigation, search

No technology is perfect, and CIWTA believe that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.

You can contact us to obtain security keys to disclose a vulnerability that you have discovered.

You are welcome to research our security implementation in a non-destructive way, for your own edification or to detect potential vulnerabilities.

Disclosure Policy

  • If you find a (potential or established) vulnerability, inform us (disclose it to us), and we will attempt to quickly resolve the vulnerability.
  • Provide us a reasonable amount of time to resolve the vulnerability before any disclosure to the public or a third-party.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
  • We will provide you with additional feedback or information and give you appropriate credit in your research, to the limitations of our other policies (eg, Privacy).

Exclusions

While researching, we'd like to ask you to refrain from:

  • Denial of service
  • Spamming
  • Social engineering (including phishing) of Tootsville operators or players
  • Any physical attempts against Violet Volts property or data centers

Thank you for helping keep Tootsville and our players safe!