TRUST CENTER
Security and responsible disclosure
How this realm protects player accounts, administrative actions, and sensitive operational data.
PLAYER ACCOUNTS
Account protection
- Game-compatible SRP6 verifiers; plaintext passwords are not stored.
- HttpOnly, SameSite sessions with server-side revocation and expiry.
- Optional authenticator codes, one-time recovery codes, and passkeys.
- Step-up authentication before sensitive account and staff actions.
- Rate limits on authentication, recovery, voting, and write endpoints.
Review your security settings →OPERATIONS
Staff accountability
- Support, commerce, moderation, realm, and administrator permissions are separated.
- Dangerous operations require reasons, explicit confirmation, and recent authentication.
- Administrative requests receive correlation IDs and immutable audit records.
- External reward and competition events require authenticated, replay-safe identifiers.
- Realm configuration changes use an allow-listed agent instead of arbitrary file access.
YOUR DATA
Privacy controls
- Character visibility, equipment, and activity can be controlled per character.
- Players can export their portal data and request reviewed deletion.
- Investigation evidence is permission-scoped and governed by retention settings.
- Payment secrets and authenticator secrets are never returned to the browser.
Open privacy controls →REPORT A PROBLEM
Responsible disclosure
Do not access another player’s account, disrupt the realm, retain personal data, or test against production without written authorization. Include the affected URL, reproduction steps, impact, and a safe proof of concept.
Contact the security team →Open a private support ticket →Reward eligibility, response targets, and safe-harbor terms are set by the realm operator. This portal does not promise a bounty unless the operator publishes one.