Skip to content
PANDA
FeaturesPricingControlPrivacy
Account Start trial
FeaturesPricingControlPrivacy Account Billing Start trial

Security

Security and Vulnerability Disclosure

How Panda handles security reports, secrets, tenant isolation, and abuse response.

Effective June 21, 2026 5 sections Document 08 of 08
Read document Acceptable use
Legal desk Security
Report channel
Support with "Security" in the subject
Testing scope
Only servers you own or operate
Secrets
Managed through deployment secret storage
Response
Triage, reproduce, fix, rotate, and preserve logs as needed
On this page
01 Security contact 02 Safe testing rules 03 Controls 04 Disclosure handling 05 Abuse response
At a glance

Security brief

  • Report suspected vulnerabilities through support with "Security" in the subject and enough detail to reproduce safely.
  • Do not test against servers you do not own, disrupt service, extract data, modify data, or publicly disclose a report before review.
  • Panda uses tenant-scoped queries, audited privileged changes, verified webhooks, server-side payment checks, and deployment secret management.
01

Security contact

Report suspected vulnerabilities through the support page with "Security" in the subject. Include reproduction steps, affected guild or account IDs if relevant, and whether any data was accessed.

Do not test against servers you do not own or operate. Do not extract, modify, delete, or disclose data while investigating.

02

Safe testing rules

Good-faith testing must avoid service disruption, persistence, social engineering, spam, credential theft, destructive actions, and access to data belonging to other servers or accounts.

If you encounter private data, stop testing, avoid further access, preserve only the minimum evidence needed to explain impact, and report through support.

03

Controls

Panda keeps Discord tokens, managed AI keys, search keys, Solana RPC credentials, and billing secrets in the deployment secret manager.

Repository queries are tenant-scoped by guild, privileged changes are audited, Discord webhooks are verified and idempotent, SOL payment signatures are verified server-side, and paid provider-spend paths check entitlements before work begins.

04

Disclosure handling

Panda triages reports by severity, reproducibility, exploitability, customer impact, and whether secrets, billing state, or server content are at risk.

Fixes may include code changes, configuration changes, key rotation, entitlement review, database corrections, customer notice, or temporary feature restrictions.

05

Abuse response

Panda can disable affected guilds, drain background work, suspend billing entitlements, revoke trial credits, rotate secrets, restore from backup, and preserve audit logs during an investigation.

Confirmed abuse may lead to account restrictions, blocked future installs, support escalation, or additional owner verification before service is restored.

Next step

Need a paper trail?

Support can route verified billing, privacy, security, export, deletion, and setup requests to the right owner context.

Report vulnerability Acceptable use ->
Related documents

Keep reading

Safety Acceptable Use Policy Rules for safe, lawful, and reliable use of Panda. Privacy Privacy Policy How Panda handles Discord server data, user memory, billing data, and support records. Reliability Status The public entry point for Panda incident and availability updates.
PANDA

Hosted Discord assistant.
Plans, controls, memory, and support for busy servers.

PRODUCT Features Pricing Account Billing Privacy Status
LEGAL Terms Privacy DPA Refunds Acceptable Use Security
SUPPORT Install Wallet account Billing Support Operator Runbook
© PandaBuilt for Discord. Managed for your server.