Security
Found something? Tell us.
We would rather hear about a problem from you than from someone else. If you have found a way to break Plurion, this page tells you where to send it and what happens next.
Contact
Write in English or French. Include what you did, what you expected, and what happened instead. A short reproduction is worth more than a long report.
What we promise
- An answer within five working days. We are a small team, so that is a real number rather than a comfortable one.
- No legal action against anyone who reports in good faith, stays within the scope below, and gives us time to fix it before going public.
- Credit if you want it, and silence if you prefer. Your call, not ours.
In scope
- · app.plurion.io — the merchant dashboard and the customer hub
- · api.plurion.io — the backend API, including the in-world endpoints
- · img.plurion.io — the image cache
- · The in-world scripts we distribute (vendors, DropBox, terminals, kiosks)
Out of scope
- · Second Life itself, and anything owned by Linden Lab
- · Findings that require a compromised viewer, or an account you do not own
- · Volumetric denial of service, and automated scanner output with no working proof
- · Missing hardening headers with no demonstrated impact
Please do not
Access, modify or delete data belonging to a merchant who is not you. If a proof of concept needs real data to be convincing, stop and describe it to us instead — we will reproduce it on our side.
There is no bounty programme
Not yet, and we would rather write that down than let you assume otherwise. What you get today is a fast answer, a fix, and credit if you want it.
This page is the Policy target of /.well-known/security.txt.