The safety of our community, systems, and users is one of our highest priorities. This covers how we handle vulnerability reports, and the strict boundaries around testing Sway's bot, API, and website infrastructure.
Found something? Here's how to report it.
If you think you've found a security issue in Sway, its dashboard, or a connected service, report it responsibly and privately.
All reports go through our Support Server. Include:
Note
We notice the people who help us stay secure.
We value the effort that goes into a responsible report. Reporters may get acknowledgment in community updates or changelogs.
Any reward or recognition is entirely at our discretion. Sway doesn't run a guaranteed public bug bounty unless we've explicitly announced one.
Good to know
What happens if a vulnerability gets used to cause harm.
If a vulnerability is found and then used against our services, users, or systems - including:
Sway can terminate access, blacklist every account involved, and pursue legal action.
Caution