Skip to content

Legal

Security and reporting a flaw

Last updated September 28, 2026

If you have found a way to read somebody else's data, act as somebody else, or make Dispresso do something it should not, we want to hear about it from you rather than from the person it happens to.

How to report something

Email security@dispresso.co. If that bounces, support@dispresso.co reaches the same people.

Useful, in rough order of how much it helps:

  • What you did, in enough detail to do it again.
  • What came back that should not have.
  • Which account or server you were using, so we can find it in the logs.
  • Roughly when.

A one line email saying "this URL returns somebody else's data" is worth far more than a polished report that arrives a week later. Send the one line.

What we promise

  • We will not come after you. Nobody who reports a flaw in good faith and inside the lines below will be threatened, sued, reported or have their account closed for it. This is the one that matters, so it is first.
  • A human reply. Not an auto responder; somebody who can actually read the report.
  • We will tell you what happened. Whether it was fixed, whether it was already known, or why we think it is not a problem. "We disagree and here is why" is a real answer and you will get it rather than silence.
  • Credit if you want it, and none if you would rather not.

What we do not promise is a payment. Dispresso does not run a bug bounty. Saying so plainly is better than a vague page that leaves somebody expecting one.

What we ask

  • Use your own accounts and your own servers. If you need somebody else's data to demonstrate it, stop and tell us what you think would happen instead.
  • If you do see somebody else's data by accident, stop there, do not save it, and say so in the report.
  • Do not degrade the service for other people: no load testing, no flooding, no mass automated scanning.
  • Do not use a flaw to take anything: coins, items, premium, somebody's account. Finding that you could is the finding.
  • Give us a reasonable chance to fix it before telling everybody.

What counts

Anything on dispresso.co, api.dispresso.co, and the Dispresso Discord application. The things most worth looking at:

  • Reading, writing or acting as another account or another server.
  • Getting round the age separation described in the under 18s policy. This one we treat as urgent whatever else is in the queue.
  • Reaching a server manager action without managing that server.
  • Making the bot post something in a server that did not ask for it.
  • Anything that moves money, currency or items in a way the product did not intend.

What does not

These come up often enough to be worth naming, so nobody spends an evening writing one up:

  • A missing security header with no exploit attached to it.
  • Output from a scanner with nothing demonstrated.
  • Somebody else's public information being public: a username, an avatar, a server listing.
  • Self inflicted problems, like pasting a token into your own browser console because something told you to.
  • Anything that needs a person to install something or hand over their password.
  • Issues in Discord itself. Those belong to Discord.

How the platform is run

Worth knowing, and it is short:

  • The site, the API, the bot and the database run on servers we operate directly. There is no third party we hand the database to.
  • Passwords, where an account has one, are stored hashed. Nobody at Dispresso can read yours, and nobody will ever ask you for it.
  • Payment card numbers never reach us: Stripe and the Discord Store handle those and we see the result, not the card.
  • Two factor authentication is available on your account and is worth turning on if you run a server.
  • Staff actions inside the admin tools are written to an audit log that the staff cannot edit.