At a glance
Security brief
- Report suspected vulnerabilities through support with "Security" in the subject and enough detail to reproduce safely.
- Do not test against servers you do not own, disrupt service, extract data, modify data, or publicly disclose a report before review.
- Panda uses tenant-scoped queries, audited privileged changes, verified webhooks, server-side payment checks, and deployment secret management.
01
Security contact
Report suspected vulnerabilities through the support page with "Security" in the subject. Include reproduction steps, affected guild or account IDs if relevant, and whether any data was accessed.
Do not test against servers you do not own or operate. Do not extract, modify, delete, or disclose data while investigating.
02
Safe testing rules
Good-faith testing must avoid service disruption, persistence, social engineering, spam, credential theft, destructive actions, and access to data belonging to other servers or accounts.
If you encounter private data, stop testing, avoid further access, preserve only the minimum evidence needed to explain impact, and report through support.
03
Controls
Panda keeps Discord tokens, managed AI keys, search keys, Solana RPC credentials, and billing secrets in the deployment secret manager.
Repository queries are tenant-scoped by guild, privileged changes are audited, Discord webhooks are verified and idempotent, SOL payment signatures are verified server-side, and paid provider-spend paths check entitlements before work begins.
04
Disclosure handling
Panda triages reports by severity, reproducibility, exploitability, customer impact, and whether secrets, billing state, or server content are at risk.
Fixes may include code changes, configuration changes, key rotation, entitlement review, database corrections, customer notice, or temporary feature restrictions.
05
Abuse response
Panda can disable affected guilds, drain background work, suspend billing entitlements, revoke trial credits, rotate secrets, restore from backup, and preserve audit logs during an investigation.
Confirmed abuse may lead to account restrictions, blocked future installs, support escalation, or additional owner verification before service is restored.
Next step Need a paper trail?
Support can route verified billing, privacy, security, export, deletion, and setup requests to the right owner context.