Taverna RoyaleSecurity Notice
Last updated: 2026-07-22 TR
Security

Security notice

Taverna Royale takes security reports seriously to protect account, payment, online match, chat, Firebase, Photon and store integrations. The primary channel for vulnerability reports is security@tavernaroyale.com.

Do not harm player data

Tests that harm a real player's account, personal data, purchase records, chat content, match outcomes, or service availability are considered unauthorized. If in doubt, submit a report first and wait for permission.

In scope Account takeover risk, unauthorized data access, payment/receipt manipulation, Cloud Functions authorization errors, Firestore/RTDB rule gaps, App Check/Auth bypass, server-authoritative match integrity, chat moderation bypass, and sensitive information leaks.
Out of scope Spam, social engineering, physical attacks, DDoS, high-volume scanning, attacks on third-party accounts, low-impact reports based on public information, and tests targeting a user's own device.
Reward program There is currently no open bug bounty or cash reward program. Submitting a report does not create a reward, fee, or employment relationship.

Safe testing rules

  • Do not read/modify data outside your own account or an explicitly permitted test account.
  • Do not manipulate match outcome, ELO, wallet, purchase or leaderboard values in production.
  • Do not exfiltrate data; a minimal screenshot, request summary, and timestamp are sufficient as evidence.
  • Do not run automated scanning, brute force, load testing, or DoS attempts that could cause a service outage.

Expected conduct

  • Give us a reasonable time to fix the issue before any public disclosure.
  • For critical reports affecting player safety, mark the subject "Critical Security".
  • If you accidentally see personal data, do not retain or share it, and state only the minimum information in the report.

Report format

  1. Short title and impact: account, payment, data, match integrity, chat, or infrastructure.
  2. Affected platform: iOS, Android, web, Firebase, Photon, or a store integration.
  3. Reproduction steps, timestamp, test account, and a request/response summary if possible.
  4. Expected behavior, observed behavior, and a suggested safe fix.
  5. An email address where we can reach you.

For non-security support requests, use support@tavernaroyale.com; for payments, billing@tavernaroyale.com; for legal notices, legal@tavernaroyale.com.

Abuse and account security

Player-safety reports such as account takeover, payment fraud, cheating, harassment, or chat safety may also be evaluated under security scope. However, for real-world physical emergencies, contact your local competent authorities.

Short summary

Report security vulnerabilities to security@tavernaroyale.com. Do not access, modify, retain, or disclose player data. Do not disrupt the service, manipulate purchases or match outcomes, and do not test on accounts that are not yours.