Security disclosure

Help us handle vulnerabilities responsibly.

This channel is for technical vulnerabilities, not account or payment support. Do not test production or use real user data.

Disclosure channel

The security mailbox is not approved yet. We do not publish a fictional address; SECURITY_EMAIL must be configured and verified before launch.

Read SECURITY.md in the project repository for the complete disclosure scope.

Yogame support

Include a concise description, reproduction steps, and expected impact without secrets.

  1. Use synthetic test accounts and data only.
  2. Share clear reproduction steps, impact, and the affected version or page.
  3. Wait for explicit approval before any test beyond a limited, safe proof.

Never send keys, access tokens, card data, private messages, or user data.

Do not perform denial-of-service, social-engineering, or data-extraction tests.