Report a vulnerability privately
Version 2026-08-18.2. A dedicated reporting channel and a narrow, non-disruptive testing boundary.
Effective and last updated 18 August 20261. Reporting channel
Send a private report to support@splatfiction.com with the subject Splatfiction security report. Include the affected URL or feature, a concise description, reproducible steps, likely impact, browser and application version, and only the minimum evidence needed.
Do not include source photographs, passwords, private keys, authentication tokens, another person's personal data, or a copy of proprietary code unless specifically requested through a secure channel.
There is no bug-bounty or reward programme and no guaranteed response or resolution time.
2. Limited written authorisation
This page is the Provider's limited written authorisation for good-faith, minimal, non-disruptive validation of a suspected vulnerability affecting the first-party Splatfiction beta at splatfiction.com, using only devices, browser profiles, installations, source files, and data that you own or are expressly authorised to use.
Within that narrow boundary, use of ordinary browser diagnostics or Inspection Tools is authorised only to the minimum extent necessary to confirm and report the suspected vulnerability. This authorisation does not permit extraction, retention, deobfuscation, reconstruction, competitive analysis, redistribution, or publication of proprietary code, binaries, shaders, methods, parameters, non-public protocols, or other Service Materials.
Activity outside this section remains governed by the Beta Use Conditions and applicable law.
3. Required testing conduct
You must:
- minimise requests, data access, and impact;
- stop immediately if you encounter another person's data, credentials, or non-public project content;
- avoid persistence, lateral movement, privilege expansion, or access beyond the minimum proof;
- avoid changing or deleting data, except disposable test data that you own;
- preserve confidentiality and report privately without unnecessary disclosure; and
- comply with applicable law and third-party provider policies.
4. Not authorised
The following are not authorised:
- denial of service, load testing, stress testing, resource exhaustion, or high-volume automated scanning;
- phishing, social engineering, physical attacks, or attacks on hosting, email, storage, DNS, or other third-party providers;
- accessing, changing, retaining, or sharing another person's data, account, browser storage, contribution package, or correspondence;
- bypassing acceptance controls for the purpose of obtaining or extracting proprietary technology;
- exfiltrating, copying, publishing, selling, or retaining proprietary code or non-public know-how;
- deploying malware, persistence, destructive payloads, or supply-chain attacks;
- extortion, threats, public disclosure before a reasonable opportunity to investigate, or disclosure of an unresolved exploit that would expose users or the Service; and
- testing an out-of-scope third-party service except through that provider's own authorised programme.
5. Scope and third parties
This policy covers first-party Splatfiction pages, application functions, and endpoints at splatfiction.com that are controlled by the Provider. A vulnerability in a third-party provider should be reported to that provider unless it results directly from Splatfiction's own configuration or integration.
Reporting does not grant a licence to copy, retain, disclose, redistribute, commercialise, or create derivative works from proprietary material.
6. Private disclosure and handling
Report privately and allow a reasonable opportunity to reproduce, assess, and remediate the issue before disclosure. The Provider may request clarification or a limited additional test. Do not publish credentials, personal data, source material, proprietary code, or implementation details that would materially facilitate exploitation.
A report that remains within this policy is treated as authorised for the contractual purposes of the Beta Use Conditions. This statement does not grant immunity from applicable law, authorise third-party rights violations, or bind an independent third party.
7. Machine-readable contact
The canonical machine-readable contact file is published at /.well-known/security.txt. The human-readable policy is this page.
Version 2026-08-18.2. Effective and last updated 18 August 2026.
Copyright © 2026 Tomáš Sikora. Splatfiction research beta. All rights reserved.