Do not publish exploitable security details, private customer information, license keys, webhook URLs, credentials, or protected product source code in a public GitHub issue.
Report security concerns privately to:
- Email:
pichirincb@gmail.com - Discord: https://discord.gg/hsx6AvBg5s
Include the affected page or resource, impact, reproduction steps, and any relevant logs with secrets removed. CB Studios will review reports and may request additional information.
This policy covers the CB Studios documentation website and repository configuration. Product vulnerabilities should identify the exact product and version. Third-party platform or dependency vulnerabilities should also be reported to the relevant upstream maintainer when appropriate.
- Do not access data that does not belong to you.
- Do not disrupt production services or customer servers.
- Do not publish a vulnerability before CB Studios has had a reasonable opportunity to investigate it.
- Do not use security research to bypass licensing, escrow, access controls, or product delivery systems.
This policy does not create a bug bounty, promise payment, or authorize activity that would otherwise be unlawful or violate applicable terms.