Selfself
Home Premium Legal
Sign in
← Legal & Policies SELF // SECURITY

Security & Responsible Disclosure

How Self protects the dashboard and how to report a vulnerability without putting users or servers at risk.

Effective October 5, 2026Version 1.75
ON THIS PAGE
1. Self’s security approach 2. Reporting a vulnerability 3. Good-faith research rules 4. No blanket authorization 5. Secrets and sensitive data 6. What happens after a report

1. Self’s security approach

Self uses layered authorization and access controls for protected dashboard, server-management, support, and administrative features. Security decisions are enforced by the service rather than relying only on what is visible in the interface.

Self uses additional request, session, abuse-prevention, and secret-isolation safeguards appropriate to the feature being used. Discord OAuth access tokens are used transiently during sign-in and are not retained by Self after the login flow completes.

2. Reporting a vulnerability

If you believe you found a security issue, use the dashboard Support Center and clearly mark the request as a security report. Include the affected page or feature, the expected behavior, what happened instead, and safe reproduction steps. Do not include credentials or unnecessary personal data.

A dedicated security contact method may be added later. Until then, the Support Center is preferred because it creates a controlled record for follow-up; the existing Self community support channel is the fallback if dashboard access is unavailable.

3. Good-faith research rules

  • Use only accounts, servers, and data you own or have explicit permission to test.
  • Use the minimum testing necessary to confirm a suspected issue.
  • Stop immediately if you encounter another person’s non-public data, credentials, private messages, or server information and report what happened.
  • Do not maintain persistence, alter or delete real data, change another user’s permissions, or take control of accounts or servers.
  • Do not perform denial-of-service, high-volume automated scanning, spam, social engineering, phishing, physical attacks, or testing against third-party systems such as Discord.
  • Give Self a reasonable opportunity to investigate and remediate a reported issue before public disclosure.

4. No blanket authorization

This policy welcomes responsible reports but does not grant unrestricted authorization to access systems, accounts, data, or third-party services. Testing outside these rules may be treated as unauthorized activity.

5. Secrets and sensitive data

Never send Discord bot tokens, OAuth client secrets, bot-control secrets, AI API keys, private keys, passwords, authentication codes, or payment credentials in a security report. If a secret is accidentally exposed, rotate or revoke it first, then report the exposure without reproducing the live secret.

6. What happens after a report

We may ask for clarification, reproduce the issue in a controlled environment, prioritize it based on impact and exploitability, deploy a mitigation, and request confirmation that the issue is resolved. Response times can vary with severity, complexity, and service availability, and this policy does not promise a specific bounty or payment.

OTHER POLICIES
Terms → Privacy → Acceptable Use →
Self logoSelf
Terms Privacy Acceptable Use Security Support
© 2026 Self. Self is not affiliated with Discord.