VEXL SMP

LEGAL

Security Policy

How we handle security on the server, the site, and the store — and how to report a problem.

Last updated July 9, 2026

01

Our approach

VEXL is a hobby project run by a small team, but we take the security of your account, your builds, and your data seriously. This page covers what's in scope, how to report a vulnerability responsibly, and what protections we already have in place.

02

Scope

  • The Minecraft server at mc.vexl.org (plugins, permissions, economy).
  • The website at vexl.org and its subdomains (status.vexl.org, shop.vexl.org).
  • Our Discord server integrations (DiscordSRV, bots we run).

Third-party services we rely on — Discord itself, Cloudflare, Supabase, and CraftingStore/Tebex — have their own security teams and disclosure processes. Please report vulnerabilities in those platforms directly to them, not to us.

03

Reporting a vulnerability

If you find a security issue — an exploit, a duplication bug, a way to bypass permissions, an auth flaw on the website, or anything similar — please report it privately via a direct message to staff on Discord rather than in a public channel. Include:

  • What you found and where (server, website, store).
  • Steps to reproduce it.
  • What you think the impact is.

We ask that you give us a reasonable window to fix the issue before discussing it publicly, and that you don't exploit it beyond what's needed to demonstrate it (no mass item duplication, griefing, or data access "just to prove it works" — a clear description is enough).

04

Out of scope

  • Social engineering or phishing attempts against staff or players.
  • Denial-of-service testing or automated vulnerability scanning without prior permission.
  • Vulnerabilities in third-party services (Discord, Cloudflare, Supabase, CraftingStore/Tebex) — report those directly to the provider.
  • Known, publicly-documented Minecraft client issues unrelated to our configuration.
05

Fair play and exploits

Using a bug for personal gain — duplicating items, draining the economy, bypassing claims or permissions — is treated as a rule violation even if you also report it. Report first, don't profit from it, and you'll generally be treated as a good-faith reporter rather than a rule-breaker.

We run Vulcan as anti-cheat on the server. Bans resulting from cheating or exploiting are published on our public ban list.

06

Account security

Secure your Microsoft/Mojang account with a strong, unique password and two-factor authentication where available — that account is the actual key to your in-game progress. VEXL staff will never DM you asking for your Minecraft or Discord password, verification codes, or payment details. Treat any message asking for these as a scam and report it to staff.

07

How we protect your data

  • All website traffic is served over HTTPS via Cloudflare.
  • Website authentication is handled by Supabase; we don't store raw passwords ourselves.
  • Payment details for store purchases never touch our servers — they're handled entirely by our PCI-compliant payment processor.
  • Server and plugin access is restricted to a small trusted staff group.
08

Our response process

We'll acknowledge your report as soon as we can, investigate, and work on a fix. Timelines depend on severity — critical issues (like a permissions bypass or auth flaw) get prioritized ahead of minor ones. If you'd like credit for the find, let us know and we'll happily mention you once it's resolved.

09

Contact

For anything security-related, DM staff on our Discord. That's the only channel we currently support for security reports.

This document describes how VEXL SMP operates in good faith and isn't a substitute for formal legal advice.