ChessMoves AI

Security & Responsible Disclosure

Last updated: 6 June 2026

We take security seriously. If you've found a vulnerability, please tell us before making it public. We commit to acknowledging all valid reports and fixing confirmed issues promptly.

How to report a vulnerability

Preferred channel — encrypted email

Email security@chessmovesai.com with:

  1. A clear description of the vulnerability and its impact.
  2. Steps to reproduce or a proof-of-concept (PoC). The simpler, the better.
  3. The URL or endpoint affected.
  4. Your name/handle (for acknowledgement, optional).

For high-sensitivity findings (credential exposure, RCE, SQLi), please encrypt your report using our PGP key at /.well-known/pgp-key.txt.

Response timeline

Scope

In scope

TargetType
chessflows.com (web app)XSS, CSRF, SQLi, auth bypass, IDOR, privilege escalation
chessflows.com/api/* (REST API)Broken access control, injection, information disclosure
WebSocket endpoint (wss://chessflows.com)Message injection, DoS, auth bypass
Authentication flowsToken forgery, session fixation, account takeover
File upload / media handlingPath traversal, stored XSS, SSRF via upload

Out of scope

CategoryReason
Denial-of-service (volumetric)Infrastructure/network attacks, not application bugs
Social engineering / phishingNot a code vulnerability
Physical access attacksOut of scope
Third-party services (Stripe, Anthropic, Lichess)Report directly to those vendors
Automated scanner output without PoCLow signal without evidence of exploitability
Missing security headers on non-sensitive pagesNot reportable without exploit
Self-XSS (requires tricking yourself)No practical impact
Outdated TLS versions without downgrade PoCLow practical risk

Rules of engagement

Please follow these rules. Violating them may result in legal action even if your finding is valid.

Rewards & recognition

ChessMoves AI does not currently operate a paid bug bounty programme. However, we offer:

Severity classification

SeverityExamples
CriticalRCE, SQLi with data exfil, full account takeover without user interaction
HighIDOR exposing private data, stored XSS, auth bypass, mass account enumeration
MediumReflected XSS, CSRF, rate limit bypass on sensitive endpoints
LowInformation disclosure (non-sensitive), open redirect, minor config issue

Safe harbour

ChessMoves AI will not pursue legal action against researchers who:

We consider good-faith security research conducted under this policy to be authorised access. We will not file complaints with law enforcement for activity within these rules.

Hall of fame

We are grateful to the following researchers who have responsibly disclosed vulnerabilities to us:

—Be the first!

Machine-readable disclosure policy: /.well-known/security.txt