generated: '2026-09-03' method: searched probe: true source: https://gzw-data.dev/.well-known/security.txt + https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md note: >- NEW THIS ROUND. On 2026-08-26 this host served no /.well-known/security.txt (404) and no policy page was found, so no disclosure artifact was written. Both now exist and were fetched live on 2026-09-03: an RFC 9116 security.txt on the production host, and a written Security Policy in the source repository. There is no paid bug-bounty program (no HackerOne / Bugcrowd / Intigriti listing was found) — this is a private-reporting VDP, which is what a single-maintainer free project would be expected to run. program_type: vulnerability-disclosure-policy bug_bounty: false policy: - url: https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md status: 200 kind: SECURITY.md contact: - mailto:security@gzw-data.dev reporting_channels: - channel: GitHub private vulnerability reporting detail: The policy directs reporters to "the private security reporting channel configured on the GitHub repository". - channel: email detail: security@gzw-data.dev, also published in the docs "Support & security" block and in security.txt. scope: in_scope: - the public read-only API - the web console - deployment configuration - the data publication workflow out_of_scope: - denial-of-service testing - quota / rate-limit bypass testing - destructive requests - systems outside the project - data-quality problems (wrong, missing or stale game data) unless they expose a security or privacy problem requested_report_contents: [description and impact, affected endpoint or commit, reproducible steps or PoC, suggested mitigation] prohibited_in_reports: [real credentials, tokens, private URLs, personal data] response_targets: published: false statement: >- "We will acknowledge a report when practicable, validate the issue, communicate an initial severity, and coordinate a fix or mitigation. Timelines depend on impact and reproducibility." No numeric SLA is committed. disclosure: coordinated: true statement: Reporters are asked to allow a reasonable remediation window before public disclosure; credit is offered on request. security_txt: file: well-known/gzw-data-security.txt fields_present: [Contact, Expires, Preferred-Languages, Canonical] fields_absent: [Policy, Encryption, Acknowledgments, Hiring, CSAF] expires: '2027-08-27T00:00:00.000Z' gap: >- The security.txt carries no Policy: field, so a machine reading only security.txt cannot reach the SECURITY.md policy. Adding "Policy: https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md" would close that with one line. evidence: - url: https://gzw-data.dev/.well-known/security.txt status: 200 fetched: '2026-09-03' kind: security.txt - url: https://raw.githubusercontent.com/ZoniBoy00/gzw-data/main/SECURITY.md status: 200 fetched: '2026-09-03' kind: security-policy - url: https://gzw-data.dev/docs/ status: 200 fetched: '2026-09-03' kind: docs "Support & security" block naming security@gzw-data.dev for private vulnerability reports