Sylvorama security policy Sylvorama is a small game run by one person. If you find a security problem in it, thank you for telling us. This page says how to report it, what you may test, and what happens next. Reporting Email security@sylvorama.world, in English, Romanian or German. Include the URL or API route, the steps to reproduce the problem, and what an attacker could do with it. Scope In scope: https://sylvorama.world, including its API under /api/ and the sign-in emails it sends. Out of scope: - denial of service, load testing, or anything else that degrades the game for its players; - social engineering, phishing and physical attacks; - sending sign-in or other emails to addresses you don't own; - Cloudflare's own infrastructure (report that to Cloudflare); - reports from automated scanners without a demonstrated impact. Testing Sign-up is by invitation. To test the signed-in game, ask security@sylvorama.world for an invitation, or two if you want to test access between accounts, and use only those accounts. While testing: - don't access, change or delete other players' data; if you reach any by accident, stop, keep no copy, and tell us; - stay within the rate limits and don't run high-volume scans; - keep only what the report needs, and delete it once we've fixed the problem. Safe harbour If you act in good faith and within this policy, we consider your research authorised, we won't pursue or support legal action against you for it, and we will work with you to understand and fix the problem. What happens next We acknowledge every report within 7 days, keep you updated, and fix confirmed problems as soon as is practical. Please wait to disclose publicly until the fix is out or 90 days have passed since your report, whichever comes first. Once it's fixed, we'll gladly credit you if you'd like. There is no bug bounty.