Poggo

Principles

  • Security by design.
  • Least privilege and defense in depth.
  • Continuous monitoring and improvement.
  • Transparency in relevant incidents.

Platform protection

  • HTTPS/TLS encrypted communication.
  • Secure authentication and access controls.
  • Environment segregation, monitoring, and audit logs.
  • Protection against automated attacks and request limiting.

Credentials and vulnerabilities

Poggo never asks for Discord passwords and uses delegated authentication when available. Responsible vulnerability reports should include a description, reproduction steps, impact, and evidence.

Incidents

In an incident, we may contain, investigate, mitigate, restore, and communicate with users or authorities as applicable.

Contact

For questions about this document, contact security@poggo.app.