LEGAL
Found a security problem in Lunar? Email it to us privately, give us a fair chance to fix it, and stay within the rules below. Good-faith research is welcome, and this page protects you while you do it. Lunar is an independent, pre-launch project run by one person, so there is no paid bounty, but we are glad to credit you.
If you find a security issue in Lunar's bot, dashboard, or API, please report it to us privately first. Email [email protected]. A short description, the steps to reproduce it, and the impact you think it has are enough to get started.
Lunar is run by one person and is still in closed beta, so there is no guaranteed response time. Reports are read and taken seriously, and we will work with you to confirm and fix valid issues. Please give us a reasonable amount of time to fix an issue before sharing it publicly.
No system is perfectly secure, and Lunar is run by one person, so this is a description of what is in place rather than a guarantee.
Ticket transcripts and moderation cases are private to the server they belong to, and require their own permission to view, separately from the rest of the dashboard.
A server can turn on encrypted logging, after which we hold ciphertext and nothing else. The keys are generated in your browser and the parts that could open them never reach us.
That quantum point is worth spelling out, because it is unusual and because the reasoning is not obvious. Encrypted logs stay sensitive for years, and anyone who copies a database today can simply keep the copy until machines exist that break the encryption protecting it. Waiting until those machines arrive would be too late for everything already stored. So Lunar seals its log keys with ML-KEM-1024, the algorithm NIST standardised for that problem, alongside the conventional one rather than in place of it, which means a weakness found in either one on its own still opens nothing.
The algorithms follow the NSA's CNSA 2.0 selection: ML-KEM-1024, AES-256 and SHA-384. To be exact about what that does and does not mean, Lunar uses those algorithms and follows that selection. It is not a certification, and we do not hold one or claim to.
Three things worth being plain about. Losing every passphrase means the logs they protect cannot be recovered, by us or by anyone. Removing a key holder stops all future access and, once the server owner runs a key rotation, removes their access to everything still stored, but it cannot retract anything they already read while they were authorised. And searching sealed logs happens in your browser, so a wide search over a long period has to download and decrypt a lot before it can show you anything.
If you make a good-faith effort to follow this page while researching, we will treat your testing of Lunar's own systems as authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue. This is the counterpart to the Acceptable use section of our Terms: research that follows this page is welcome, not a breach of those terms.
This safe harbor covers Lunar's own bot, dashboard, and API only. It cannot authorize testing against Discord, Cloudflare, or any other third party; for those, follow their own security policies.
To stay within good faith and the safe harbor above:
Lunar is an independent, pre-launch project run by one person, and there is no paid bug bounty. Reports are handled purely on a good-faith basis. If you report a valid issue and would like recognition, we are glad to credit you by name or handle once it is resolved, and you are equally welcome to stay anonymous.
Report a vulnerability or ask a question: email [email protected]. See also our Privacy Policy and Terms of Service.