NekoByte does not currently operate a public bug-bounty program. Responsible disclosures are still welcome through the contact path below.
Submit suspected vulnerabilities via email to [email protected]. Include reproduction steps, impact, affected endpoints, and any logs or proofs of concept. Please avoid sensitive data in attachments.
If your report involves distribution, licensing, or paid-build behavior, specify whether the issue relates to the NekoByte client or the Steam-distributed build.
If you follow this policy, act in good faith, avoid privacy violations, and do not exploit data beyond what is necessary to demonstrate the issue, we will not pursue or support legal action related to your research. Please give us reasonable time to remediate before public disclosure.
For actively exploited vulnerabilities, flag your report as "URGENT" in the subject line of your email to [email protected]. We prioritize real-time threats to installers or user data protection.
We may update this policy as our infrastructure, release process, or reporting procedures change.