1. Safe Harbor Commitment
If you conduct vulnerability research in good faith in accordance with this policy, we will not initiate legal action against you. We consider your research to be authorized and helpful to the ecosystem.
2. Reporting Guidelines
Please report security vulnerabilities directly to our security pod at devsamp1st@gmail.com with:
- Step-by-step reproduction instructions and Proof of Concept (PoC).
- Affected domain, endpoint, API version, or parameter.
- Potential impact assessment (e.g. IDOR, privilege escalation, injection).
3. Out of Scope
Denial of Service (DoS/DDoS) attacks, social engineering of DevSamp staff, and automated spamming of public forms are strictly prohibited and outside our safe harbor scope.
Fast Response Guarantee
Our senior security architects acknowledge incoming vulnerability reports within 24 hours.