1. How to report
Email support@discovertcg.com with “DiscoverTCG security report” in the subject.
Please include enough for us to reproduce the issue:
- The affected URL, endpoint or screen.
- The steps to reproduce it, and what an attacker could achieve.
- Any proof-of-concept request, payload or screenshot.
- How you would like to be credited, if you would like to be.
Report it even if you are not certain, and even if you cannot fully demonstrate impact.
2. Scope
In scope:
- The
discovertcg.comwebsite and its subdomains. - The DiscoverTCG application, once publicly released.
- Authentication, account, store and community functionality.
Out of scope:
- Denial of service, volumetric testing, or anything that degrades the service for other people.
- Social engineering of our team, our stores or our users, and any physical testing.
- Vulnerabilities in third-party platforms we use — report those to the provider.
- Reports produced solely by an automated scanner, with no demonstrated impact.
- Missing hardening headers, or best-practice findings with no exploitable consequence.
3. What we ask, and what we promise
If you follow this policy in good faith, we will treat your research as authorised, will not pursue action against you over it, and will work with you on a fix.
In return, we ask that you:
- Only ever test against your own accounts and data.
- Stop as soon as you have confirmed a vulnerability, and never access, alter, download or retain another person’s information.
- Do not degrade, disrupt or damage the service.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
- Comply with the law. Nothing here authorises anything unlawful.
4. What we will do
- Acknowledge your report, and aim to do so within two working days.
- Assess and confirm the issue, and tell you what we found.
- Keep you updated while we work on a fix, and let you know when it is resolved.
- Credit you publicly if you would like us to.
We do not currently run a paid bug bounty. We are a small pre-launch team, and we would rather be honest about that than imply a reward we cannot pay.
5. Our own practices
DiscoverTCG is in active development, and our security posture will develop with it. Currently the public website is a static site served over HTTPS with HSTS, and it sets no advertising or analytics cookies — see our cookie notice.
As accounts, location data and store information come into the product, we will describe our handling of them in our privacy notice and expand this page.
6. security.txt
A machine-readable version of this policy is published at /.well-known/security.txt, following RFC 9116.
7. Contact
Security reports: support@discovertcg.com. For anything that is not a security issue, use our contact page.