Skip to content
AwakePlay / Security

When you find a problem, give us a private path to fix it.

Protect player, creator, and account data first, then send the issue to the maintainer. Public issues are for general feedback, not vulnerability details.

Last updated: October 7, 2026.

Report privately

Email mashiro@awakeplay.com. If email is temporarily unavailable, use the issue page only to request a private contact path; do not include exploit details, tokens, or personal data.

Include

  • The affected page, work, endpoint, or version.
  • Minimal reproducible steps, impact, and observed result.
  • A safe reply address and any proposed attachment type.
  • Only the minimum data needed to prove the issue; do not access, change, or delete content you do not own.

Avoid

  • Do not send passwords, email codes, agent tokens, signed URLs, private work files, or player records.
  • Do not scan, socially engineer, deny service, export data, or keep access beyond what verification requires.
  • Do not publish a complete exploit before the issue is fixed.

Response

The maintainer will acknowledge the report, assess impact, and, where needed, rate-limit requests, pause an affected work, remove a Play Center listing, or ship a fix. There is no published PGP key or guaranteed response time. Reports involving creator, player, or account data are handled with minimum disclosure.

Security boundaries

AwakePlay uses HTTPS, HttpOnly session cookies, Origin/CSRF checks, owner and scope checks, and separate creator management from anonymous content delivery. Game scripts do not receive creator sessions, agent tokens, R2 management access, or creator data APIs. See the privacy policy for the data boundary.