Security

Responsible Disclosure

If you have discovered a security issue in SaveWave.lol infrastructure, our CDN, or a release we published, we want to know. This page describes what is in scope, how to report, and what to expect.

How to Report a Vulnerability

Email security@savewave.lol with:

  • A clear description of the issue
  • Steps to reproduce, including URLs, request data, or payloads
  • The potential impact you believe the issue has
  • Any proof of concept you can share
  • Your preferred contact method if you want a reply

If you require encrypted communication, request our PGP key in your first email and we will send it before you share sensitive details.

What Is In Scope

  • The savewave.lol website and its server-side components
  • Our download CDN and release integrity endpoints
  • Any published release binary that does not match the published SHA-256 hash
  • Authentication, authorization, or session handling issues in our infrastructure
  • Server-side request forgery, injection, or deserialization issues

What Is Out of Scope

  • Vulnerabilities in Wave Executor itself — contact the developers directly
  • Roblox platform or client vulnerabilities — report to Roblox
  • Denial-of-service attacks or volumetric testing
  • Automated scanner output without demonstrated impact
  • Social engineering of our staff or users
  • Issues requiring a compromised user device or physical access
  • Reports about missing security headers without a demonstrated exploit
  • Third-party services we do not control (Cloudflare, hosting providers, etc.)

Response Expectations

  • Initial acknowledgment: within 72 hours
  • Triage decision: within 7 days
  • Status update: every 14 days until resolved
  • Public disclosure: coordinated with you; we aim for 90 days after the fix ships

Safe Harbor

If you make a good-faith effort to comply with this policy during your research, we will not pursue legal action against you and we will not report you to law enforcement for the reported issue. Good faith means:

  • You do not access, modify, or exfiltrate data that is not your own
  • You do not degrade our services or the services of our providers
  • You do not use the vulnerability for personal gain
  • You give us reasonable time to fix the issue before public disclosure

This safe harbor does not extend to third parties whose services we use. It also does not protect against claims from parties whose data you accessed without authorization.

What We Will Not Do

  • We will not pay bug bounties. We do not currently operate a paid bounty program.
  • We will not require you to sign an NDA before triage. We may request confidentiality for sensitive issues until a fix is deployed.
  • We will not ask for unnecessary personal information.

Credit

If you wish to be credited for a valid report, tell us the name or handle you want used and a link to your profile. We publish credits in the changelog after the fix ships. We will not credit you without your explicit request.

Our Infrastructure

For transparency about what we run:

  • Static site hosted behind a global CDN with WAF
  • Release binaries served from object storage with published SHA-256 hashes
  • HTTPS enforced with HSTS and modern TLS
  • Security headers including CSP, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy
  • No user accounts, no login system, no stored user data

Contact

Security reports: security@savewave.lol

All other inquiries: see Contact.

Related Pages

Safety Center

Antivirus flags, scan results, and SHA-256 verification.

Safety Center →

Verify SHA-256

Confirm the file you downloaded matches what we published.

Verification Guide →

Changelog

Security notes for every release.

Changelog →

Contact

Other contact channels.

Contact →