Reporting a Security Issue
Last updated: September 15, 2026
Found a bug?
If you've found a security vulnerability in GameSwapz -- a way to bypass payment, access another user's data, inject code, or anything else that shouldn't be possible -- please tell us privately before testing it further or sharing it publicly. We take these reports seriously and will fix confirmed issues quickly.
How to report
Email security@gameswapz.com with a description of the issue, the steps to reproduce it, and (if relevant) which account/order/listing you used to test it. Please avoid automated scanning, testing against real buyers' or sellers' accounts and orders, or actions that could disrupt the service (e.g. mass account creation, denial-of-service testing) -- test against your own account and data wherever possible.
What we ask
Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly. Do not access, modify, or delete other users' data beyond what's needed to demonstrate the issue. Do not use a vulnerability to move real funds, place real orders against real sellers, or otherwise cause real-world harm -- proof of concept is enough.
What you can expect from us
An acknowledgement of your report, honest communication about whether/when it will be fixed, and credit (if you'd like it) once resolved. GameSwapz doesn't currently run a paid bug bounty program, but we're grateful for good-faith reports and will consider a thank-you for anything serious.