Vulnerability Disclosure Policy

As a company founded to combat censorship, we believe in peer review. That's why we support the independent security community to help us maintain the security of our platform and protect sensitive information from unauthorized disclosure. We encourage security researchers to contact us to report potential vulnerabilities identified in PlayHouse products.

This policy specifies:
  • What systems and applications are in scope;
  • What types of security research methods are covered;
  • How to report potential security vulnerabilities to us; and
  • Our vulnerability disclosure philosophy and how long we will ask you to wait before publicly disclosing vulnerabilities.

PlayHouse will acknowledge receipt of reports that comply with vulnerability disclosure policy within five (5) business days. Upon receipt, we will endeavor to validate submissions, implement corrective actions (if appropriate), and inform researchers of the disposition of reported vulnerabilities with minimum delay.

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized per PlayHouse's legal safe harbor policy. We will work with you to understand and resolve the issue quickly and will not recommend or pursue legal action against you for any of your action(s) related to your research.

Test methods

Security researchers must not:
  • Test any system other than the systems set forth in the Scope section below;
  • Disclose vulnerability information except as set forth in the Reporting a vulnerability and Disclosure sections below;
  • Engage in physical testing of facilities or resources;
  • Engage in social engineering;
  • Send unsolicited electronic mail to PlayHouse users, including “phishing” messages;
  • Execute or attempt to execute “denial of service” or “resource exhaustion” attacks;
  • Introduce malicious software in the systems of PlayHouse or any third party;
  • Perform tests that could degrade the operation of PlayHouse systems or intentionally impair, disrupt, or disable SEC systems;
  • Test third-party applications, websites, or services that integrate with or link to or from PlayHouse systems;
  • Delete, alter, share, retain, or destroy PlayHouse data, or render PlayHouse data inaccessible;
  • Interact with an individual account (which includes modifying or accessing data from the account) without the account owner's explicit consent in writing, which you must produce upon request;
  • Use an exploit to exfiltrate data, establish command line access, establish a persistent presence on PlayHouse systems, or “pivot” to other PlayHouse systems;
  • Exploit a security issue you discover for any reason other than for testing purposes, and you do not conduct testing outside of your own account, a test account, or another account for which you have the explicit written consent of the account owner to test. (This includes demonstrating additional risk, such as the risk that the security issue could be used to compromise sensitive company data or another user's account);
  • Be a resident of, or make your submission from, a country against which Australia has issued export sanctions or other trade restrictions;
  • Be employed by or a contractor/vendor of PlayHouse or its subsidiaries or affiliates, or be an immediate family member of a person employed by PlayHouse or its subsidiaries or affiliates (defined for these purposes as including spouse, domestic partner, parent, legal guardian, legal ward, child, and sibling, and each of their respective spouses, and individuals living in the same household as such individuals); or
  • Be less than 18 years of age - if you are at least 18 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating.
Security researchers may:
  • View or store PlayHouse nonpublic data only to the extent necessary to document the presence of a potential vulnerability.
Security researchers must:
  • Cease testing and notify us immediately upon discovery of a vulnerability;
  • Cease testing and notify us immediately upon discovery of an exposure of nonpublic data;
  • Purge any stored nonpublic data upon reporting a vulnerability;
  • Make a good faith effort to avoid privacy violations and disruptions to others, including (but not limited to) unauthorized access to or destruction of data, and interruption or degradation of our services. You must not intentionally violate any applicable laws or regulations, including (but not limited to) laws and regulations prohibiting unauthorized access to data;
  • If you inadvertently access another person's data or PlayHouse company data without authorization while investigating an issue, you must promptly cease any activity that might result in further access of user or PlayHouse company data and notify PlayHouse what information was accessed (including a full description of the contents of the information) and then immediately delete the information from your system. Continuing to access another person's data or company data may demonstrate a lack of good faith and disqualify you from any benefit of the Safe Harbor Provisions described below. You must also acknowledge the inadvertent access in any related vulnerability report you may subsequently submit. You may not share the inadvertently accessed information with anyone else; and
  • Give us reasonable time to investigate and mitigate an issue you report before publicly disclosing any information about the report or sharing such information with others. You will receive updates from us regarding the status of your report and our progress toward resolution. Given that every vulnerability is different, the timing, extent, and verbosity of our updates to you will also differ, and will be within PlayHouse's sole discretion.
Scope

This Vulnerability Disclosure Policy applies to any digital assets owned, operated, or maintained by PlayHouse, including our websites, mobile applications, APIs, and other online services.

We encourage security researchers, ethical hackers, and the broader security community to identify and report potential vulnerabilities that could impact the confidentiality, integrity, or availability of PlayHouse’s systems and user data.

If you discover a security vulnerability within the defined scope, we request that you report it in a responsible manner following the guidelines outlined in this policy.

The following systems and services are in scope:

  • Our website, playhouse.fans;
  • Creator, fan, and agency account systems;
  • Payment processing and transaction security;
  • Messaging, media sharing, and content delivery mechanisms; and
  • PlayHouse APIs and associated services.
Any services not explicitly listed above are excluded from the scope of this policy. For clarity, this includes, but is not limited to:
  • Spam;
  • Social engineering techniques, phishing, or attempts to manipulate PlayHouse staff or users;
  • Distributed Denial-of-Service (DDoS) attacks or automated scanning that could disrupt service availability;
  • Content injection is out of scope unless you can clearly demonstrate a significant risk to PlayHouse or its users;
  • Executing scripts on sandboxed domains;
  • Security issues outside the scope of PlayHouse’s mission;
  • Bugs that require exceedingly unlikely user interactions;
  • WordPress bugs (please report those to WordPress);
  • Bugs on help.playhouse.fans and playhouse-hq.zendesk.com (please report those to Zendesk);
  • Proof of concepts that require physical access to the device;
  • Out-of-date software — For a variety of reasons, we do not always run the most recent software versions, but we do run software that is fully patched;
  • Flaws impacting out-of-date browsers; and
  • Issues related to third-party services or integrations not directly controlled by PlayHouse.
Reporting a vulnerability

Reports are accepted via our dedicated from at playhouse.fans/security or electronic mail at [email protected]. Acceptable message formats are plain text, rich text, and HTML.

  • We prefer reports that include proof-of-concept code demonstrating an exploitation of the vulnerability.
  • Reports should provide a detailed technical description of the steps required to reproduce the vulnerability, including a description of any tools needed to identify or exploit the vulnerability.
  • Images (e.g., screen captures) and other documents may be attached to reports. It is helpful to give attachments illustrative names.
  • We request that any scripts or exploit code be embedded into non-executable file types.
  • We can process all common file types and archives, including zip, 7zip, and gzip.

Researchers may submit reports anonymously or provide contact information, including how and when the PlayHouse Security team should contact them. We may contact researchers to clarify aspects of the submitted report or gather other technical information.

By submitting a report to PlayHouse, you affirm that the report and any attachments do not violate the intellectual property rights of any third party. You also grant PlayHouse a non-exclusive, royalty-free, worldwide, perpetual license to use, reproduce, create derivative works, and publish the report and any attachments.

Safe Harbor Provisions
  • We consider these terms to provide you authorization, including under the Computer Fraud and Abuse Act (CFAA) and similar applicable laws and/or regulations, to test the security of the products and systems identified as in-scope above. These terms do not provide you authorization to intentionally access company data or data from another person's account without their express consent, including (but not limited to) personally identifiable information or data relating to an identified or identifiable natural person.
  • If PlayHouse determines in its sole discretion that you have complied in all respects with these Vulnerability Disclosure terms in reporting a security issue to PlayHouse, we will not initiate a complaint to law enforcement or pursue a civil action against you, to include civil actions under the CFAA in connection with the research underlying your report and DMCA claims against you for circumventing the technological measures we have used to protect the applications in scope. PlayHouse will also not pursue legal action against you for clear accidental or good faith violations of its policy or these terms.
  • Your use of PlayHouse technologies, including for purposes of this program, remains subject to PlayHouse Terms and Policies. To the extent activities authorized by these Vulnerability Disclosure terms are inconsistent with other terms of service for in-scope PlayHouse technologies and programs, we waive those restrictions for the limited purpose of permitting security research under this policy.
  • If legal action is initiated by a third party against you for conduct that PlayHouse determines to have complied with these Vulnerability Disclosure terms, PlayHouse will take steps to make it known, either to the public or the court, that your actions were authorized under this program.
Disclosure

PlayHouse is committed to the timely correction of vulnerabilities. We will work diligently to resolve any issues that put our community at risk. We ask all researchers to bear with us as we examine the reports you submit to us, as the public disclosure of a vulnerability in the absence of a readily-available corrective action likely increases rather than decreases our community’s security risk.

Accordingly, we require that you refrain from sharing information about discovered vulnerabilities for 120 calendar days after you have received our acknowledgement of receipt of your report. If you believe others should be informed of the vulnerability prior to our implementation of corrective actions, you must coordinate in advance with the PlayHouse Security team.

We may share vulnerability reports with affected vendors. We will not share the names or contact data of security researchers unless given explicit permission.

Questions?

Questions regarding this policy may be sent to [email protected]. PlayHouse encourages security researchers to contact us for clarification on any element of this policy.

Please contact us if you are unsure if a specific test method is inconsistent with or unaddressed by this policy before you begin testing. We also invite security researchers to contact us with suggestions for improving this policy.

Last updated: January 2025