Status: V7 security-program design. Source: fills the planning gap identified
in V1_V7_PLAN_SET_AUDIT_2026-06-12.md §6.2 (no VDP/bounty program). Grounded
in V7/V7_ARCHITECTURE.md (arch§"The WASM Sandbox", arch§"The Trust Boundary
— Platform vs. Realm", arch§"Determinism — The Cross-Cutting Invariant",
arch§"Testing, Eval Gates, and Golden Replays"), V7/V7_features.md
(features§"Launch Readiness" — the zero-escape gate, features§"Incident
Response"), V7/V7_DEPENDENCIES.md §3 (Wasmtime pinned) and §4 (sandbox =
the security keystone), and V7/ADVERSARIAL_EVAL_GATES.md
(sandbox-escape, trust-boundary, currency-firewall, identity-leak
gates). Owner: platform security lead (program), Sekhmet lead (triage
rotation), legal (safe harbor). Date: 2026-06-12.
1. Why V7 Specifically Needs This#
V7's thesis is "run untrusted creator code safely"
(features§"Design Posture" 2). The internal bar is a sandbox-escape corpus
with zero escapes (features§"Launch Readiness", sandbox-escape gate) — but a
corpus only contains the attacks its authors imagined. A platform whose
security keystone is one subsystem (deps§4: "a sandbox escape invalidates the
whole thesis") needs the world's attackers economically aligned with its
defenders. The VDP is that alignment: pay well for sandbox escapes, make
research legally safe, and respond on clocks that beat the gray market.
Program phases: private bounty (invited researchers, creator alpha) → public VDP, paid bounty by invitation (RP beta) → fully public bounty (economy launch — the program must be public before real money flows; planning assumption adopted 2026-06-12).
2. Scope#
2.1 In scope (asset tiers)#
| Tier | Assets | Why this tier |
|---|---|---|
| T-Critical | Ixchel sandbox escape (WASM guest → host code-exec, capability forgery, tier-policy bypass); trust-boundary breach (realm code or creator web-view reaching platform tokens/secrets/PII — the trust-boundary gate's live form); attested-client integrity bypass enabling platform-wide cheating; RCE on platform plane; CSAM/child-safety control bypass |
Each invalidates a launch-readiness invariant (features§"Launch Readiness") |
| T-High | Economy exploits crossing the firewall (play-currency → real-money bridge, the currency-firewall case; payout-formula manipulation; entitlement forgery); auth/identity (account takeover, identity-leak deanonymization across realms, ban evasion at the platform layer); Sekhmet scan bypass (malicious artifact served as cleared) |
Real-money and identity harm |
| T-Medium | Realm isolation (one realm's code/data affecting another realm; BYOC node → platform-plane lateral movement attempts; Nephthys cross-aggregate access); mesh authority confusion (dual-writer/zero-owner windows beyond the mesh-handoff gate); anti-cheat signal suppression; moderation/report-pipeline bypass |
Cross-tenant and integrity harm |
| T-Low | In-realm-only exploits with no cross-boundary effect (single-realm dupes — operators have recovery tooling, V7/docs/world-state-rollback.md); rate-limit gaps; non-sensitive info disclosure |
Real but bounded; rewarded modestly to keep reports flowing |
2.2 Out of scope#
Social engineering of staff/operators; physical attacks; volumetric DDoS
(report capacity findings, don't demonstrate them); findings requiring a
jailbroken/rooted client beyond what attestation already models; roleplay
content disputes (that's moderation); vulnerabilities in operators' own
off-platform infrastructure (report to the operator; the platform's BYOC
conformance interest is covered by V7/docs/operator-data-protection.md);
testing against production realms with real players — sandbox-escape and
economy research must use the researcher-test realms the program provisions
(free Dedicated realm + test accounts per enrolled researcher).
3. Safe Harbor#
Published verbatim in the policy (language follows the DOJ CFAA good-faith-research policy and industry-standard safe-harbor clauses; counsel to finalize):
Research conducted in good faith and in material compliance with this policy is authorized. We will not initiate or support legal action (CFAA or analogous computer-misuse law, DMCA §1201 anti-circumvention, or ToS breach claims) against you for it, and we waive those restrictions to the extent they would bar good-faith research under this policy. If a third party initiates action over policy-compliant research, we will state on record that your research was authorized. Good faith means: access only what is needed to demonstrate the issue; use program-provisioned test realms and accounts; no exfiltration of other users' data beyond minimal proof (and immediate deletion on report); no degradation of live service; no monetization of the finding outside this program; report promptly and keep details confidential until coordinated disclosure completes.
Anti-cheat carve-in, stated explicitly: probing the attested client and EAC integration is in scope under safe harbor when done on test accounts — client-integrity research is exactly what the platform most needs and is the area researchers most fear ToS retaliation on (planning assumption adopted 2026-06-12; coordinate terms with the EAC vendor contract).
4. Reward Bands#
Benchmarked against the 2025–2026 market: platform sandbox/VM escapes clear $20k–$100k+ at majors (browser/V8 sandbox escapes, hypervisor escapes); game-platform criticals (Roblox-class programs) run $10k–$30k; economy/auth highs $2k–$15k. Planning assumption adopted 2026-06-12; bands reviewed annually against market and program signal quality. Payouts via Aje's KYC/tax rails (the infrastructure exists — features§"The Creator Economy").
| Class | Band | Notes |
|---|---|---|
| Sandbox escape (guest→host exec or capability forgery) | $25,000–50,000 | Top of program; full chain with platform-plane impact hits the cap; novel technique bonus +20% |
| Trust-boundary breach (platform secret/PII reachable from realm plane) | $10,000–35,000 | Scales with what's reachable (token < credential < PII at scale) |
| Attested-client integrity bypass (platform-wide) | $10,000–30,000 | Coordinated with EAC vendor |
| Child-safety control bypass | $10,000–30,000 | Plus immediate-fix posture (§5) |
| Economy: currency-firewall bridge / payout manipulation / entitlement forgery | $2,500–10,000 | To the cent matters: the payout-formula gate's live form |
| Auth/identity: ATO, cross-realm deanonymization, platform ban evasion | $2,500–15,000 | ATO without user interaction tops the band |
| Realm isolation / mesh authority / Nephthys cross-aggregate | $1,000–7,500 | |
| Sekhmet scan bypass | $1,500–7,500 | |
| In-realm-only exploits (dupes etc.), rate limits, minor disclosure | $150–1,000 | Dupes also feed the Crucible balance corpus (features§"AI Balance Verification") |
Program budget planning assumption adopted 2026-06-12: $500k/year reserve; a quarter consuming >50% triggers a security review, not a budget defense — heavy valid-report flow means the corpus and SDL need work.
5. Triage SLAs and Process#
Triage rotation: platform security + Sekhmet, with subsystem owners (Ixchel/Moremi for sandbox, Abundantia for economy) on tap. Clocks (planning assumptions adopted 2026-06-12):
| Step | SLA |
|---|---|
| Acknowledge receipt | ≤24 h |
| Triage to severity + reproduce | ≤72 h (T-Critical: ≤24 h) |
| T-Critical mitigation | ≤48 h patch-or-mitigate (see §6 for the dependency-CVE variant) |
| T-High fix | ≤14 days |
| T-Medium fix | ≤60 days |
| Bounty decision | ≤14 days from triage; payment ≤30 days from acceptance |
| Researcher status updates | At triage, fix, and disclosure; never silent >30 days |
Every accepted finding produces, mandatorily: (1) a regression test in the
owning adversarial gate's corpus (a sandbox escape becomes a permanent
sandbox-escape fixture — the corpus grows by exactly the attacks the world
invents; this is the program's compounding value), and (2) an incident-record
entry; T-Critical findings additionally trigger the incident-response
playbook (features§"Incident Response") including the
quarantine-by-content-hash sweep where an exploit shipped in any artifact.
6. The Wasmtime-CVE Response Posture#
The sandbox is built on Wasmtime, pinned (deps§3). Upstream CVEs are a when, not an if (precedent class: guard-page/bounds-check miscomputation CVEs in Cranelift-compiled code). Standing posture:
- Subscribe + pre-coordinate: security@ contact registered with the Bytecode Alliance advisory list; target membership in pre-disclosure embargo channels as the program matures. On-call owns the feed.
- 48-hour patch-or-mitigate commitment from advisory publication (or
embargo notification) for any CVE plausibly reachable in V7's
configuration: either roll the pinned version (fast-path build: the AOT
.cwasmcache is keyed on compiler version — arch§"Dependency Resolution" — so a Wasmtime bump triggers a coordinated recompile of the AOT artifact cache; the rebuild pipeline must sustain full-catalog recompile in ≤24 h, a stated capacity requirement for the upload pipeline, planning assumption adopted 2026-06-12), or apply configuration mitigation while the roll proceeds. - Configuration mitigations available by design (kept tested, not
theoretical — exercised quarterly in a game-day): disable the affected
Wasm proposal/feature flag (the deterministic profile already runs with
relaxed-SIMD and threads off — arch§"Determinism", narrowing exposure);
force-throttle or suspend the affected sandbox tier (e.g., suspend
Native-tier loads, drop community uploads to Scripted) — realms degrade
per the degrades-safely promise (features§"V7 Product Promise") rather
than going dark; emergency-disable JIT paths everywhere (production
already runs
enable_compiler(false)— arch§"The WASM Sandbox" — so upload-pipeline AOT is the only compiler surface, and it can be paused unilaterally: publish stalls, play continues). - Metering interaction, explicitly: fuel and epoch interruption are liveness controls, not memory-safety boundaries — a Wasmtime memory-safety CVE is not mitigated by metering, and the response plan never treats "budgets are on" as a reason to downgrade severity. Two real interactions are tracked instead: (1) determinism — a Wasmtime version roll can change fuel accounting or codegen, so golden replays (arch§"Testing, Eval Gates, and Golden Replays") run against the new pin before fleet rollout, and replay-affecting changes are release-noted to creators with replay fixtures; (2) epoch-tier code (cosmetic/UI, non-deterministic metering) rolls first since it has no replay-equivalence constraint, giving a canary population for the new runtime.
- Version-roll drill: the full pin-bump → AOT-recompile → golden-replay → staged-fleet-rollout pipeline is exercised on a scheduled (non-emergency) Wasmtime upgrade at least quarterly, so the 48 h commitment rests on a rehearsed path.
7. Coordinated Disclosure Timelines#
- Default: 90 days from triage to public disclosure, or at fix deployment + 14 days, whichever is sooner; mutual extension for genuinely hard fixes (mesh-authority redesigns), capped at 180 days except under upstream embargo.
- Upstream-involved findings (a V7 report that is actually a Wasmtime/ Agones/EAC bug): the platform handles upstream coordination, the researcher's credit and bounty are preserved, and timeline follows the upstream embargo.
- Researcher publication: encouraged after coordination completes — public technical write-ups of paid findings (with platform review for player-targeting details) are reputation fuel for the program. Hall of fame + severity-tiered swag for VDP-only (unpaid-tier) reporters.
- Public reporting: program stats (reports, payouts, median SLAs) published annually; T-Critical incidents follow the public incident-report commitment (features§"Incident Response").
- Child-safety findings: never publicly detailed beyond "a control gap was fixed"; regulator notification per counsel where applicable.
8. Program Metrics#
Quarterly review, owner: platform security lead. Targets are planning assumptions adopted 2026-06-12: ≥95% SLA adherence on ack/triage clocks; median time-to-mitigate T-Critical ≤48 h (measured from report, drilled quarterly); ≥1 externally-reported sandbox-class finding converted to corpus fixture per quarter once public (zero external findings with a growing researcher base is a signal the program isn't attracting talent — raise bands); duplicate-report rate <30%; researcher NPS on triage interaction ≥+30; zero safe-harbor disputes.