Vulnerability Disclosure Policy
COREGAME welcomes good-faith reports that help protect Takamol4 and its users.
How to report
Email support@coregamedev.com with a clear description, affected URL or component, reproduction steps, impact, and supporting evidence.
Safe-harbor expectations
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and disruption, do not access or modify data beyond what is necessary to demonstrate the issue, do not use social engineering or denial-of-service techniques, give us reasonable time to remediate, and comply with applicable law.
Out of scope
Physical attacks; employee social engineering; spam; denial of service; automated high-volume scanning; reports based only on missing non-critical headers; clickjacking on pages without sensitive action; self-XSS; known vulnerable library versions without demonstrated impact; and issues in third-party services not controlled by COREGAME.
Our response
We aim to acknowledge valid reports within 5 business days, provide status where appropriate, and remediate based on severity and risk. We do not currently offer a guaranteed bounty. Public disclosure must be coordinated in writing.
Privacy
Do not include personal data in reports unless necessary. Any accidentally accessed personal data must not be retained, copied, or disclosed.
