Security & Responsible Disclosure
Version information loading…
Measures in place
Passwords are hashed by our authentication provider and never stored in readable form; leaked-password screening is enabled.
All traffic uses HTTPS/TLS, and API access is authenticated per request.
Database access is governed by row-level security so users can only reach their own records; privileged operations run server-side.
Administrative capabilities are role-based (super admin, legal admin, moderator, support, finance, security) with least-privilege access, and staff actions are written to audit logs.
Uploaded videos and avatars are held in private storage and served through expiring links.
Card and bank details are handled by the payment processor — Creator Battles never stores raw card numbers.
Abuse prevention includes vote-fraud detection, duplicate-account signals and fraud review before payouts.
Reporting a vulnerability
Email [not yet configured] with steps to reproduce and impact. Please give us a reasonable time to fix an issue before publishing it.
Do not access other people's data, degrade the service, or run automated scanning that harms availability. Good-faith research reported this way will not be pursued by us.
Account security on your side
Use a unique password, keep your email account secure, and review the sessions and privacy settings in Settings. Password resets are sent to your registered email address only.
These templates and application controls are designed to support legal and platform compliance but do not constitute legal advice. Creator Battles should have the final policies and business model reviewed by a qualified attorney before launch.
