Security
Last updated
The short version
- Email security@skyscrap.fun with details and steps to reproduce.
- We'll acknowledge it within five working days and keep you posted.
- Good-faith research under these rules won't face legal action from us.
- Don't test against real players, and don't run denial-of-service tests.
This summary is for convenience; the full text below is what applies.
Reporting a vulnerability
If you think you’ve found a security problem, email security@skyscrap.fun. Please include:
- what the problem is and what someone could do with it;
- the address, page or part of the game affected;
- step-by-step instructions to reproduce it, with screenshots or a short video if that helps; and
- how you’d like to be credited, if at all.
We’ll acknowledge your report within five working days, keep you updated while we work on it, and tell you when it’s fixed. Please give us a reasonable time to fix the problem before you share details publicly.
In scope
- skyscrap.fun and its subdomains, including where the game is hosted;
- the Skyscrap game client;
- our game servers and APIs, once online play launches.
Out of scope
- denial-of-service, load or stress testing;
- social engineering, phishing, or physical attacks against people or property;
- other companies’ services and platforms; please report those to them;
- reports from automated scanners without a demonstrated impact; and
- cheating in matches against bots, which run entirely on your own device. Please do tell us about ways to cheat in online play.
Rules for research
- Only test against accounts and data you own or have permission to use.
- Don’t access, change or delete other players’ data beyond the minimum needed to show the problem.
- Don’t degrade the service for others, and don’t use a weakness against real players.
- Stop and tell us as soon as you find personal data or a serious problem.
Safe harbour
If you act in good faith and follow this policy, we won’t take legal action against you or report you to the authorities for your research, and we’ll treat your work as authorised. If in doubt about something, ask us first.
Thanks
We don’t run a paid bug bounty yet, but we’re happy to credit researchers who help us, with their permission. Our machine-readable contact details are in security.txt.