# Security contact for quranadventure.com # # Published because a vulnerability disclosure policy is a line item on school # district security rubrics and on the CISA Secure by Design pledge, and # because somebody who finds a problem should not have to guess where to send # it. RFC 9116. # # Keep Expires in the future. An expired security.txt reads as an abandoned # service, which is worse than not publishing one. Contact: mailto:info@resourcesforislamicschools.com Expires: 2027-09-11T09:09:47Z Preferred-Languages: en Canonical: https://quranadventure.com/.well-known/security.txt Policy: https://quranadventure.com/support # What we would like to hear about, in rough order of how much it would worry # us. This platform holds no personally identifying information of its own: # accounts are optional, and the database stores an opaque identifier and an # assigned handle. So the things that matter most are about other people's # data and about children. # # 1. Anything that exposes one player's data to another player. # 2. Anything that lets a request act as a player it is not. # 3. Anything that writes to another player's scores or saved games. # 4. Anything that causes a real name or an email address to be displayed. # # Please do not run automated scanners against the games during school hours in # North America. Tell us what you would like to test and we will make a window. # # We have no bug bounty. We will credit you if you would like to be credited, # we will answer, and we will tell you when it is fixed.