Security
Reporting a security vulnerability
If you have found a security vulnerability in the Embershroud game client or in the online services it needs to run, we want to hear about it.
Email: [email protected]
If email fails: message us on our Discord and ask for the operator. Do not post vulnerability details in a public channel.
Iterative Studios AB is a small studio. A person, not a robot, reads this address, and we will get back to you. There is no paid bug bounty.
What helps
- What the problem is and what an attacker could do with it.
- The steps to reproduce it, and the game version, platform, and approximate time.
- How we can reach you if we need to ask a question.
What to leave out
Please send only what is needed to understand and reproduce the problem. Do not send passwords, tokens, or other credentials; other players' personal data, chat, or screenshots that identify them; health, political, religious, sexual, ethnic, or similar sensitive information; or information about criminal offences. If a report cannot be explained without one of these, tell us that first and we will agree a way to handle it.
Please do not access, change, or delete other players' data, degrade the service for others, or hold a vulnerability back for payment. Our terms of service still apply - they restrict modifying the client, connecting through unofficial interfaces, and probing our protocols - and this page does not lift them. As our terms say, a good-faith report will never on its own be treated as a violation. If you think you need to go further than ordinary play to demonstrate something, contact us first and we will talk about it.
What we do with your report
We use your report to investigate and fix the problem and to meet our reporting duties under EU product-security law. Where the law requires it, we report actively exploited vulnerabilities and severe security incidents to the authorities through the EU Single Reporting Platform; those reports identify the product and the problem, not you.
How we handle your information
- Controller: Iterative Studios AB, org. nr 559392-0605, Sweden.
- What we keep: your email address and anything you choose to put in your report.
- Why, and on what basis: to receive, assess, and fix reported vulnerabilities and to run our product-security process - our legitimate interest in the security of our product and our players (Art. 6(1)(f) GDPR); and, where a report becomes a reportable vulnerability or incident, to meet a legal obligation (Art. 6(1)(c) GDPR).
- Who sees it: the operator of Iterative Studios AB. Our email provider processes the message on our behalf. Where a report is reportable, we submit it through the EU Single Reporting Platform, which passes it to the coordinating national CSIRT, ENISA, and onward to other national CSIRTs and market-surveillance authorities where EU law requires.
- How long: we keep the message thread while we work on the report and for up to 12 months after it is closed, then delete it. Alongside it we keep an internal technical case record, filed under a case reference and written so that it does not name you, for up to 24 months after closure, so we can show what we did.
- Your rights: you can ask for access to, correction of, or erasure of your personal data, and you can object to our processing based on legitimate interest. Write to [email protected]. You can complain to the Swedish Authority for Privacy Protection (IMY). Erasing your contact details may mean we cannot come back to you about the report; the technical case record stays because it does not name you.