Responsible Disclosure Program

At LootLocker, security is a top priority. We take the security of our systems, our products, our employees and our customers' information seriously, and we value the security community.

We always want to hear from security researchers who have found a potential issue. This page explains how to reach us, what is in scope, what we will and won't act on, and what we commit to in return.

Before you start

Please follow these rules. They exist to protect our customers, their players, and you.

  • Don't degrade the service. No attacks — including denial of service — that degrade the user experience, disrupt production systems, or destroy data.
  • Don't initiate fraudulent financial transactions.
  • Don't cause harm. Avoid any activity that could cause harm to LootLocker, our customers, or our employees.
  • Stay in your own account. Do not attempt to access another user's account or data. You may only access, disclose and report issues you tested on accounts you own.
  • Stop if you find personal data. Do not store, share, compromise or destroy LootLocker customer data. If you encounter personally identifiable information, halt your activity immediately, purge the related data from your systems, and contact us straight away. This protects potentially vulnerable data, and it protects you.
  • Report it to us first, and keep it confidential. Keep information about any vulnerability you discover confidential between you and LootLocker until we consider the issue resolved.
  • Stay in scope. Only the core LootLocker platform is in scope. Third-party services, and any service not directly controlled by LootLocker, are not.
  • Use the channel below. Report through the address in "How to report", and please don't chase us for updates — see "What happens next".

What is in scope

The core LootLocker platform: our APIs, the web console, and the services we operate directly.

Not in scope: third-party services, anything we do not directly control, social engineering, and physical attacks on infrastructure.

What we won't act on

These are not eligible for acknowledgment or recognition. Reporting them is not a breach of this program — it just won't go anywhere.

  • Vulnerabilities that cause no state change, such as clickjacking with no consequence
  • Features reported as vulnerabilities
  • Bugs requiring unlikely user interaction — for example, a cross-site scripting flaw that needs the victim to type the payload in themselves
  • Vulnerabilities affecting only users of outdated browsers
  • Account brute force
  • Mixed content warnings
  • Error information that cannot be used for a direct attack
  • Unverified output from automated tools or scanners
  • Text typos
  • Password strength reports
  • Issues already known to us, or already reported by someone else

How to report

Email [email protected] with your contact details and as much detail as you can, in clearly written English:

  • Every step needed to reproduce the vulnerability
  • Logs and screenshots
  • A video demonstration, where that helps
  • The IP addresses you tested from
  • Any other supporting evidence

The more precisely a report reproduces, the faster it gets fixed.

What happens next

If you have followed the rules above, we commit to:

  • Not pursuing or supporting legal action related to your research.
  • Working with you to understand and resolve the issue quickly.
  • Recognizing your contribution in our Security Researcher Hall of Fame, if you are the first to report the issue and we make a code or configuration change as a result.

We do not commit to a response time. Please don't contact us asking for updates on a report — if we consider the report eligible, we will respond, and reports that are not eligible will not receive a reply.

We reserve the right, at our sole discretion, to decide that a report is invalid — for example because the issue is already known to us, or is not sufficiently severe.

Changes to this program

We may change these terms at any time. Changes are posted on this page and take effect immediately on posting. These terms apply from the moment you disclose an issue to us.