How your bot and account are kept safe
What we do, what we do not do yet, and how to tell us about a problem. Plain words, no badges.
Your server
- Each server runs in its own container with a hard memory limit, so a busy neighbour cannot take memory from yours.
- A server cannot reach our private network or anyone else's server on it, and cannot send email directly (the mail ports are closed), so the platform cannot be used as a spam relay.
- New outgoing connections are rate-limited per server. A bot needs a handful; a scanner needs thousands.
- When a server connects out, we note when, where and which server (never what was sent) and keep that for 14 days, so an abuse report points at the right server instead of everyone's. See the privacy policy.
Your bot token
- It lives in your server's settings and is handed to your bot when it starts.
- Crash alerts include your bot's last lines of output with tokens removed.
- Anyone you give access to your server in the panel can read it. That is how the panel works, so only share access with people you trust, and see keeping your token safe.
Your account and payments
- Two-step verification is available on every account, and required for ours. See your account.
- Repeated failed sign-ins from one address get that address blocked from the panel for about an hour.
- Card details go to Stripe and never touch this site or our servers.
What is not done yet
Daily backups are kept on the same machine as your server. That protects against mistakes and bad plugins, not against the machine failing; the off-site copy is built but not switched on yet. Until it is, keep your own copy of anything you cannot lose.
How changes are made
Anything that can be reached from the internet (a page that takes input, a route, a server setting) is reviewed the way an attacker would look at it before it goes live, with tests for what the review finds, and the review is recorded. The billing service is fed hostile requests on every change.
Reporting a problem
Found a flaw? Email [email protected] or open a ticket from the contact page, and give us a fair chance to fix it before telling anyone else. There is no bug bounty; we will read the report properly, say what we did about it, and credit you if you want. Our security.txt says the same.
To report abuse by a customer instead, use the contact page and say it is an abuse report: it goes to the front of the queue.