Security & Responsible Disclosure
Planetia takes security seriously. If you discover a bug or vulnerability, please follow the process below. Good-faith researchers are protected and rewarded.
Exploit Reporting Instructions
Send a detailed report to security@planetia.org. Include:
- A clear description of the vulnerability
- Steps to reproduce (proof-of-concept where possible)
- Potential impact assessment
- Your in-game username (for reward delivery)
We acknowledge all reports within 48 hours and commit to a 90-day coordinated disclosure timeline — we fix critical issues before public disclosure.
PGP key for encrypted reports: coming soon — not yet published. Email reports in plaintext to security@planetia.org until a key is available.
Non-Punishment Guarantee
We will never ban or penalise accounts for reporting exploits in good faith, even if you discovered the vulnerability by accident during normal gameplay. This guarantee applies as long as the report is submitted before exploiting the bug for in-game advantage.
Cosmetic Bug-Bounty Reward
Reporters of valid Critical or High severity exploits receive a cosmetic item grant as a thank-you reward. Rewards are processed within 7 days of issue validation by our staff. We do not offer monetary rewards at this time.
Severity classification follows the CVSS v3.1 standard.
Exploit Clause
The following constitutes prohibited exploitation (not eligible for reward, may result in account suspension regardless of report):
- Repeatedly triggering a bug to gain in-game resources, credits, or ranking advantage
- Sharing or publishing exploit details before coordinated disclosure
- Using an exploit to affect other players' accounts or data
- Accessing data beyond your own player account
What constitutes legitimate testing: discovering a bug in normal gameplay, testing it once to confirm reproducibility, then immediately reporting it.
For general support, visit our Game Manual or join our Discord. For privacy/GDPR requests, contact privacy@planetia.org.