Contact: mailto:security@sleepyy.wtf Contact: https://discord.gg/NReWWceHKP Expires: 2027-05-23T00:00:00.000Z Preferred-Languages: en Canonical: https://sleepyy.wtf/.well-known/security.txt Policy: https://sleepyy.wtf/tos # Scope # sleepyy.wtf and all *.sleepyy.wtf subdomains are in scope. Out of scope: # - User-uploaded content (responsibility of the uploading user) # - Third-party services we integrate with (Discord, Stripe, Cloudflare, etc.) # - Social-engineering of staff or users # - DoS / volumetric attacks # # Bring a working PoC for anything you report. Bounties are case-by- # case for confirmed RCE / auth bypass / mass IDOR / stored XSS. We # do not currently run a formal bug bounty program.