Security Policy
This policy explains TORVIX's primary security controls, incident-response approach, and how to report vulnerabilities responsibly.
1. Technical and organizational measures
- HTTPS/TLS for web and API traffic.
- HttpOnly, Secure, and SameSite session cookies; CSRF protection; and Discord OAuth state validation.
- Server-scoped authorization and verification of Discord management permissions for each action.
- Encrypted storage of sensitive application data and no exposure of secret keys to the client.
- Rate limiting, security-event records, access logs, and suspicious-login protection.
- Regular backups, controlled deployments, and security updates.
- Signature, timestamp, order-matching, and replay protection for PayNow webhooks.
2. Access security
Access to production systems and secrets is limited to authorized people who need it to operate the service. Discord community moderators and third-party server administrators do not have direct access to TORVIX production data.
3. Security incident response
Suspected incidents are handled through detection, containment, investigation, remediation, and prevention steps. If a personal-data breach occurs, affected controllers and required authorities are notified within applicable legal time limits.
Because TORVIX does not retain card details, incidents involving card data are also governed directly by the relevant payment provider's procedures.
4. Vulnerability reporting
If you believe you found a vulnerability, email destek@torvixbot.xyz with the subject 'Security Vulnerability Report' and include the affected area, potential impact, and safe reproduction steps.
Do not disclose details publicly before the issue is resolved, and test only to the minimum extent required to confirm the vulnerability.
5. Authorized testing boundaries
The following testing is expressly prohibited and is not considered responsible security research:
- Accessing, changing, or exporting data belonging to another user or server.
- DDoS, intensive automated scanning, resource exhaustion, or testing that causes service disruption.
- Social engineering, phishing, targeting employees/users, or physical attacks.
- Collecting more data than necessary to demonstrate a vulnerability or establishing persistence.
- Publishing production secrets, tokens, or payment data.
6. Rewards and safe harbor
TORVIX does not operate a general or guaranteed bug-bounty program. Recognition, Premium access, or a reward for a responsible good-faith report may be considered on a case-by-case basis.
This policy does not authorize unlawful activity or conduct that disrupts the service.