1. Self’s security approach
Self uses layered authorization and access controls for protected dashboard, server-management, support, and administrative features. Security decisions are enforced by the service rather than relying only on what is visible in the interface.
Self uses additional request, session, abuse-prevention, and secret-isolation safeguards appropriate to the feature being used. Discord OAuth access tokens are used transiently during sign-in and are not retained by Self after the login flow completes.
2. Reporting a vulnerability
If you believe you found a security issue, use the dashboard Support Center and clearly mark the request as a security report. Include the affected page or feature, the expected behavior, what happened instead, and safe reproduction steps. Do not include credentials or unnecessary personal data.
A dedicated security contact method may be added later. Until then, the Support Center is preferred because it creates a controlled record for follow-up; the existing Self community support channel is the fallback if dashboard access is unavailable.
3. Good-faith research rules
- Use only accounts, servers, and data you own or have explicit permission to test.
- Use the minimum testing necessary to confirm a suspected issue.
- Stop immediately if you encounter another person’s non-public data, credentials, private messages, or server information and report what happened.
- Do not maintain persistence, alter or delete real data, change another user’s permissions, or take control of accounts or servers.
- Do not perform denial-of-service, high-volume automated scanning, spam, social engineering, phishing, physical attacks, or testing against third-party systems such as Discord.
- Give Self a reasonable opportunity to investigate and remediate a reported issue before public disclosure.
4. No blanket authorization
This policy welcomes responsible reports but does not grant unrestricted authorization to access systems, accounts, data, or third-party services. Testing outside these rules may be treated as unauthorized activity.
5. Secrets and sensitive data
Never send Discord bot tokens, OAuth client secrets, bot-control secrets, AI API keys, private keys, passwords, authentication codes, or payment credentials in a security report. If a secret is accidentally exposed, rotate or revoke it first, then report the exposure without reproducing the live secret.
6. What happens after a report
We may ask for clarification, reproduce the issue in a controlled environment, prioritize it based on impact and exploitability, deploy a mitigation, and request confirmation that the issue is resolved. Response times can vary with severity, complexity, and service availability, and this policy does not promise a specific bounty or payment.