Responsible disclosure guidelines for Munch. Play. Kink.
Found a vulnerability? Email security@munchplaykink.com before disclosing publicly. We commit to acknowledging your report within 3 business days and resolving critical issues within 72 hours. See Section 5 for safe harbor terms.
Munch. Play. Kink. ("MPK", "we", "us") takes the security of our platform and the privacy of our members seriously. Given the sensitive nature of the communities we serve, we hold ourselves to a high standard of responsible security practice.
We welcome good-faith security research. If you discover a vulnerability, please report it to us rather than disclosing it publicly. We commit to working with you promptly and transparently.
In scope:
• munchplaykink.com and all subdomains
• API endpoints at munchplaykink.com/api/*
• Authentication and session management
• Member data handling and access controls
• File upload and media storage
• Payment flows (CCBill redirect, NowPayments webhook)
Out of scope:
• Third-party services we integrate with (CCBill, NowPayments, Resend, Cloudflare R2, Neon) — report those directly to the respective vendor
• Social engineering attacks against staff or members
• Physical security
• Denial-of-service attacks — do not attempt to disrupt the platform
• Automated scanning that generates excessive load
• Vulnerabilities requiring physical access to a member's device
Email security@munchplaykink.com with:
• A clear description of the vulnerability and the potential impact
• Steps to reproduce, including any relevant request/response data
• The URL, endpoint, or component affected
• Any proof-of-concept (screenshots, curl commands, redacted payloads)
Please do not include actual member data in your report. If you have inadvertently accessed member data, note that in your report and do not retain, share, or use it.
PGP: We do not currently publish a PGP key. If you need to encrypt a report, contact us first and we will arrange a secure channel.
Acknowledgement: Within 3 business days of receiving your report.
Triage: Within 7 business days we will assess severity and confirm whether we can reproduce the issue.
Resolution timeline (targets):
• Critical (RCE, auth bypass, mass member data exposure): 72 hours
• High (IDOR, significant data leak, payment bypass): 7 days
• Medium (XSS, CSRF, limited data exposure): 30 days
• Low / informational: 90 days
We will keep you informed of our progress. If you have not heard back within 5 business days of submission, please follow up.
We consider good-faith security research conducted in accordance with this policy to be authorised and will not pursue civil or criminal action against researchers who:
• Report the vulnerability to us before any public disclosure
• Do not access, modify, delete, or exfiltrate member data beyond what is necessary to demonstrate the vulnerability
• Do not disrupt platform availability or degrade member experience
• Do not exploit the vulnerability for personal gain or disclose it to third parties before we have resolved it
We ask for a reasonable coordinated disclosure window — typically 90 days from our acknowledgement — before you publish. We are happy to credit you (by name, handle, or anonymously, your choice) after the fix ships.
We do not currently operate a paid bug bounty program. We offer:
• Public credit on our security acknowledgements page (coming soon)
• Complimentary membership for significant, confirmed findings at our discretion
Reports that are out of scope, non-reproducible, already known, or that violate this policy are not eligible for credit.
We also cannot accept reports for:
• Missing security headers with no demonstrated exploitability
• Clickjacking on pages with no sensitive actions
• Self-XSS (you injecting into your own session)
• Brute-force attacks (rate limiting is already enforced)
• Theoretical vulnerabilities with no working proof of concept
Security reports: security@munchplaykink.com
General contact: support@munchplaykink.com
This policy is published at https://munchplaykink.com/security-policy and referenced in /.well-known/security.txt per RFC 9116.
Last updated: June 24, 2026