Facepunch Studios Ltd looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe. This program covers all of our currently released game, their servers and their backends.

Response Targets

Facepunch Studios Ltd will make a best effort to meet the following SLAs for hackers participating in our program:

Type of Response SLA in business days
First Response 5 days
Time to Triage 10 days
Time to Bounty 35 days
Time to Resolution depends on severity and complexity

We’ll try to keep you informed about our progress throughout the process.

Disclosure Policy

Program Rules

Dependencies

Out of scope vulnerabilities

When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope:

Safe Harbor

Golden Standard Safe Harbor applies.

Thank you for helping keep Facepunch and our users safe!