Security

Responsible disclosure

waves.ac is a security product, so we take our own security seriously. If you believe you have found a vulnerability, we want to hear from you.

How to report

Email security@waves.ac with a clear description, steps to reproduce, and the impact. Please do not open public issues for security bugs.

What we promise

We acknowledge reports within 72 hours, keep you updated, and will not pursue legal action against good-faith research that follows this policy.

In scope

waves.ac, api.waves.ac, and the dashboard. Auth, ingest, tenant isolation, and anything that could expose another customer's data.

Out of scope

Denial of service, social engineering, physical attacks, spam, and automated scanner output without a demonstrated impact.

Our commitments

  • Passwords are stored only as a memory-hard hash; two-factor secrets and Open Cloud keys are encrypted at rest and never leave the backend.
  • Each customer's data is isolated from every other customer's at the database layer; the platform operator console reads only through narrow, audited paths and every read is logged.
  • We never collect a Roblox player's IP, hardware ID, or MAC address; identity is a graph of legitimate signals keyed on the Roblox account.

Machine-readable policy: /.well-known/security.txt