Security
Responsible disclosure
waves.ac is a security product, so we take our own security seriously. If you believe you have found a vulnerability, we want to hear from you.
How to report
Email security@waves.ac with a clear description, steps to reproduce, and the impact. Please do not open public issues for security bugs.
What we promise
We acknowledge reports within 72 hours, keep you updated, and will not pursue legal action against good-faith research that follows this policy.
In scope
waves.ac, api.waves.ac, and the dashboard. Auth, ingest, tenant isolation, and anything that could expose another customer's data.
Out of scope
Denial of service, social engineering, physical attacks, spam, and automated scanner output without a demonstrated impact.
Our commitments
- Passwords are stored only as a memory-hard hash; two-factor secrets and Open Cloud keys are encrypted at rest and never leave the backend.
- Each customer's data is isolated from every other customer's at the database layer; the platform operator console reads only through narrow, audited paths and every read is logged.
- We never collect a Roblox player's IP, hardware ID, or MAC address; identity is a graph of legitimate signals keyed on the Roblox account.
Machine-readable policy: /.well-known/security.txt