Security

Found a hole? Tell us at[email protected] with “Security” in the subject. Machine-readable version:/.well-known/security.txt.

What we promise

  • We will confirm your report and tell you what we found.
  • We will not pursue legal action against you for research done in good faith under the rules below.
  • We will credit you when we fix it, if you want the credit.
  • We do not run a paid bounty programme. If that changes, this page changes with it.

What we ask

  • Report privately first and give us reasonable time to fix it before you publish.
  • Use your own account. Do not touch other players' data, balances, or matches.
  • No denial of service, no spam, no load testing against production.
  • Do not use social engineering against our team or our players.
  • Stop as soon as you have proved the issue. You do not need to extract data to demonstrate access.

In scope

  • The Gammon Rivals mobile app.
  • Our backend: authentication, match and economy endpoints, and the database rules behind them.
  • This website, at gammonrivals.com.

Out of scope

  • Third-party services we use but do not run, including the app stores and our hosting and authentication providers. Report those to them.
  • Findings from automated scanners with no demonstrated impact.
  • Missing hardening headers or best-practice warnings with no exploit path.
  • Reports that only show that a client can be modified. Match rules, dice, and payouts are decided on the server, so a modified client is expected to change nothing — but if you can prove otherwise, that is a real finding and we want it.

What to include

  • What you did, step by step, so we can reproduce it.
  • What an attacker gains from it.
  • The account, device, and rough time you tested, so we can match it to our logs.
  • Any screenshots or request captures that make it obvious.

Player account problems

This page is for vulnerabilities. If your own account has been taken over or you see charges you do not recognise, go to Supportinstead — that gets a faster answer.