Security
Security Contact And Disclosure
WarpIntel is built as a third-party EVE Online advisory app with public tools first and private EVE data gated behind feature-specific consent. This page explains how to report a security concern without exposing private player, corporation, alliance, or account data.
What To Send
- The affected page, route, API endpoint, or feature name.
- Clear reproduction steps, expected behavior, and actual behavior.
- Impact in plain language, including whether another user or private EVE data may be affected.
- Approximate time, browser/device context, and any visible error text.
Safe Testing Boundaries
- Do not access, change, delete, export, or publish another user's data.
- Do not submit secrets, private tokens, private EVE data, or production credentials unless we request them.
- Do not run denial-of-service, spam, social engineering, phishing, or automated abuse tests.
- Do not attempt to bypass EVE Online, CCP, Discord, Stripe, Google, Resend, Vercel, Neon, or other provider controls.
Protect Sensitive Information
Do not include passwords, EVE tokens, private account exports, payment details, or unrelated personal data in a security report.
