Vulnerability Disclosure Policy
Effective date: September 28, 2026
1. Purpose
1.1 Summer Labs, Inc., a Delaware corporation ("Summer", "we", "us"), located at 2810 N Church St, STE 89812, Wilmington, DE 19802, United States, operates Summer Games, a UGC games platform used by Creators and Players, including minors aged 13 to 17. Security research conducted in good faith makes our Users safer, and this Vulnerability Disclosure Policy (this "Policy") exists to make that research safe for the researcher too.
1.2 This Policy describes what systems are in scope, what conduct is authorized, how to report vulnerabilities, and what we commit to in return. Capitalized terms not defined here have the meanings in the Summer Dictionary.
1.3 This Policy applies to everyone who tests or reports vulnerabilities in Summer systems, whether or not they hold an Account.
2. Authorization and safe harbor
2.1 Authorization. If you conduct security research in good faith, making a good faith effort to comply with this Policy ("Good-Faith Research"), Summer authorizes that research with respect to the systems in scope under Section 3. Good-Faith Research means accessing systems solely to identify, investigate, or report a security vulnerability or weakness, in a manner designed to avoid harm to Summer, our Users, and their data, and otherwise consistent with the rules in Sections 4 through 6.
2.2 Safe harbor. To the fullest extent our authorization can reach, and for Good-Faith Research only: (a) we consider your research authorized access under the Computer Fraud and Abuse Act (18 U.S.C. Section 1030) and under applicable state anti-hacking laws, including California Penal Code Section 502, and we will not initiate or support a civil claim or criminal referral against you under those laws for that research; (b) we waive any claim against you under the Digital Millennium Copyright Act, 17 U.S.C. Section 1201, for circumvention of technological measures that we use on in-scope systems where the circumvention was performed solely as part of Good-Faith Research, and we will not bring a claim under the DMCA and Intellectual Property Policy for that circumvention, provided that this waiver covers only technological measures that Summer itself uses and does not extend to the technological measures or claims of third-party licensors whose components are included in in-scope systems (if such a licensor acts against you, Section 2.3 applies); (c) we waive enforcement of any provision of the Summer Games Terms of Service, the Summer Engine Desktop EULA, the Developer Tooling and API Terms, or other Additional Terms that would otherwise prohibit Good-Faith Research (such as restrictions on security testing, reverse engineering for security analysis, or automated access), solely to the extent of the conflict and solely for the duration and purposes of the Good-Faith Research; and (d) we will not pursue legal action against you, and will not ask law enforcement to investigate you, for Good-Faith Research.
2.3 Third parties. We cannot authorize testing of systems we do not own or operate, and this safe harbor does not bind third parties (for example, our infrastructure providers, Stripe, Persona, Steam, or Apple, whose App Store, in-app purchase and StoreKit systems bill Sparks Pack purchases made in the Summer iOS app under Apple's terms and issue the Apple receipt; Summer licenses the Sparks). If a third party initiates legal action against you for research that complied with this Policy, we will, upon your request, make it known that your activities were conducted under this Policy and with our authorization.
2.4 Interpretation. If you are ever uncertain whether your planned research is consistent with this Policy, ask us first at support@summerengine.com before proceeding. We will resolve genuine ambiguity in this Policy in favor of researchers acting in good faith.
2.5 What this is not. This Policy is not an invitation to exploit vulnerabilities, harvest data, extort payment, or degrade service. Conduct outside Good-Faith Research is not authorized and receives no safe harbor.
3. Scope
3.1 In scope. The following Summer-owned and Summer-operated systems are in scope: (a) the production Summer Games platform, including web properties at summerengine.com and subdomains we operate; (b) the Summer Engine desktop application and Editor, including its update mechanism; (c) Summer-published game client and server runtimes, including the Exported Game runtime; (d) Summer public and authenticated APIs, including those covered by the Developer Tooling and API Terms; (e) the Hosting Services infrastructure endpoints we expose (multiplayer, matchmaking, relay), as governed by the Multiplayer Hosting Terms; and (f) vulnerabilities in the Platform economy and ledger systems (Sparks, Purchased Sparks, Earned Sparks, Game Data and Game Points, Program Payments under the Summer Creator Program, Network Share computation), subject to the special rules in Section 6.
3.2 Out of scope. The following are out of scope, and testing them is not authorized by this Policy: (a) social engineering of any kind, including phishing, vishing, or pretexting against Summer employees, contractors, Creators, or Players; (b) physical attacks or physical intrusion against Summer offices, data centers, personnel, or property; (c) denial of service, resource exhaustion, or volumetric attacks of any kind, including load testing against production systems; (d) third-party services and systems, including Stripe (payments powered by Stripe, including Stripe Global Payouts and Summer's Stripe financial account), Persona (identity verification and sanctions screening), Apple (the App Store, in-app purchase and StoreKit systems, which bill Sparks Pack purchases made in the Summer iOS app under Apple's terms and issue the Apple receipt), Steam and other distribution platforms, cloud infrastructure providers' own control planes, and any vendor systems, even where they integrate with Summer (report suspected issues in those integrations to us; report issues in the third party's own systems to that third party); (e) individual Creators' Games, Mods, and game-specific server code, except that you may report vulnerabilities you observe in them to us under Section 3.3; (f) attacks that require a stolen device, stolen credentials you were not issued, or a compromised account belonging to someone else; (g) spam, content policy violations, and moderation evasion as such (report those through the reporting tools referenced in the Summer Games Community Standards); and (h) findings with no plausible security impact, such as missing best-practice headers without a demonstrated exploit, clickjacking on pages with no sensitive action, and version banners alone.
3.3 Creator content. If you discover a vulnerability in a specific Creator's Game or Mod (as opposed to the Platform itself), report it to us at support@summerengine.com. We will coordinate with the Creator. Do not exploit it against Players and do not disclose it publicly before coordinated disclosure under Section 9.
3.4 Test environments. Where we operate designated staging or sandbox environments for researchers, prefer them over production. Their addresses, if available, will be published at summerengine.com/legal/security.
4. Rules of engagement
4.1 Test only with Accounts you own and control. Create test Accounts using your own email address, and where the intake form allows, register your researcher handle with us. Do not test using another person's Account or credentials.
4.2 Access, copy, and retain the minimum data necessary to demonstrate the vulnerability. A proof of concept should use your own test Accounts and your own data wherever possible. Never use a vulnerability to browse, search, or enumerate other Users' data beyond the minimum needed to prove the issue exists.
4.3 Do not violate anyone's privacy. Do not exfiltrate, download in bulk, modify, or delete data belonging to Summer or to any User. Do not intercept or monitor other Users' traffic or communications, including in-game chat.
4.4 Do not degrade the experience of Players or Creators. Do not disrupt live game sessions, matchmaking, or the Hosting Services. Automated scanning must be rate-limited and must stop if it causes instability.
4.5 Do not pivot. If a vulnerability gives you access to internal systems, credentials, keys, or infrastructure, stop at the point of proof. Do not use discovered credentials or access to reach further systems, establish persistence, or install backdoors.
4.6 Do not publicly disclose, sell, trade, or share the vulnerability or any data obtained through it with anyone other than Summer, except as permitted by the coordinated disclosure process in Section 9.
4.7 Delete all copies of any non-public data obtained during research once the report is resolved, and confirm deletion on our request.
4.8 Comply with all applicable laws. This Policy does not authorize conduct that is unlawful independent of the computer access itself.
5. Personal data and minors: stop and report
5.1 Summer Games is used by minors, and the protection of their data is our highest priority, reflected in the Summer Games Privacy Policy and the Child Safety and CSAE Policy.
5.2 If your research exposes personal data of any User beyond your own test Accounts, you must: stop the specific test immediately; take no additional copies; report the exposure to support@summerengine.com without delay, marked clearly as involving personal data; and preserve nothing except what we ask you to preserve for verification. Every reported exposure of personal data beyond your own test Accounts opens Summer's internal security incident process and a breach analysis under applicable law, whether or not your research complied with this Policy; Summer may have notification duties to affected Users, to parents or to authorities even where the access was by a compliant researcher, and Summer's own notifications do not narrow the safe harbor in Section 2.
5.3 If the data appears to belong to a minor, or relates to parental controls, Parent Accounts, Age Checks or identity verification, or chat and social features involving minors, treat Section 5.2 as strict: stop everything, report immediately, retain nothing. Do not attempt to verify a minor's identity or contact any User.
5.4 If your research surfaces content or conduct implicating child safety, report it immediately through the channel in the Child Safety and CSAE Policy in addition to support@summerengine.com. Do not download, store, or forward any such content under any circumstances; describe where it can be found instead.
6. Virtual economy testing rules
6.1 Vulnerabilities in Sparks purchase flows, purchase eligibility (age of majority) checks, the Purchased Sparks and Earned Sparks ledgers, Game Data and Game Points handling, Program Payment computation and delivery under the Summer Creator Program, Network Share computation, and Summer's own App Store Purchase receipt validation and Sparks Pack crediting (Apple's App Store, in-app purchase and StoreKit systems themselves are out of scope under Section 3.2(d)) are in scope and valuable to us. Apple in-app purchase of Sparks Packs runs in every launch country from launch day, including Japan, Brazil and Argentina; for Japan, Summer monitors the total unused Purchased Sparks balance held by Players in Japan against the Payment Services Act threshold (JPY 10,000,000 outstanding at the 31 March and 30 September test dates) and completes the prepaid payment instrument notification or registration and the issuance deposit before that threshold is reached, so that until then Summer is within the exemption.
6.2 If you find a way to create, duplicate, move between Accounts, or misvalue Sparks, Earned Sparks, Game Points, Virtual Content, or Program Payment amounts: demonstrate it only against your own test Accounts, keep the amounts minimal, report immediately, and do not spend, convert into a Program Payment or platform credit, or otherwise benefit from any balance created. We will reverse test balances as part of remediation, and you agree we may do so. Nothing in this Section 6 characterizes Sparks, Earned Sparks or Game Points as property, stored value or a deposit; those terms keep the meanings and the limited-license basis given in the Summer Games Terms of Service, whose vocabulary governs this Section.
6.3 Do not test real payment flows with real payment instruments beyond a single minimal transaction on your own Account if strictly necessary, and never test with anyone else's payment instrument. Stripe's and Apple's own systems are out of scope under Section 3.2(d).
6.4 Attempting to convert a vulnerability into money or goods (for yourself or anyone else) is exploitation, not research, and is outside the safe harbor.
7. How to report
7.1 Channel. Send reports to support@summerengine.com. If Summer adopts a managed intake platform such as HackerOne, which is planned only when the bounty program in Section 10 launches, its program page will be identified at summerengine.com/legal/security and will become the preferred channel; until then this mailbox is the channel. An encryption key for sensitive reports will be published at summerengine.com/legal/security [PGP KEY PLACEHOLDER].
7.2 What to include. A good report includes: a description of the vulnerability and its class; the affected product, endpoint, or version (including Engine or Editor version where relevant); step-by-step reproduction instructions; a minimal proof of concept; your assessment of impact; and, if personal data was encountered, a clear statement of what was seen and what was retained. Include a way to reach you for follow-up. You may report anonymously, but we cannot update you or credit you without contact information.
7.3 One issue per report where practical. If you believe an issue is being actively exploited in the wild, say so prominently; active exploitation reports are triaged first.
8. Our commitments
8.1 Acknowledgment. We will acknowledge receipt of your report within 3 business days.
8.2 Triage and updates. We will triage your report, aim to communicate an initial assessment within 10 business days, and provide status updates at reasonable intervals until resolution, including when a fix ships.
8.3 No retaliation. We will not suspend, terminate, or otherwise penalize an Account because its holder conducted Good-Faith Research and reported under this Policy, and we will not treat a compliant report as a violation of the Summer Games Terms of Service.
8.4 Transparency with you. If we determine that your conduct fell outside this Policy, we will tell you which conduct and which provision before taking any further step, except where doing so would be unlawful or would create a risk to Users.
8.5 Credit. With your consent, we will credit you on our security acknowledgments page at summerengine.com/legal/security once the issue is resolved. You may decline credit or report anonymously.
9. Coordinated disclosure
9.1 We ask that you keep vulnerability details confidential and give us 90 days from your report before any public disclosure. We will work in good faith to remediate well within that window and will tell you when a fix has shipped.
9.2 If remediation requires longer than 90 days (for example, an Engine vulnerability requiring Creators to rebuild Exported Games), we will explain why and propose a revised disclosure date; we ask that you not disclose while we are working the issue diligently and keeping you informed.
9.3 After remediation, or after the agreed disclosure date, you may publish your findings, provided your publication does not include Users' personal data, working exploit code for still-unpatched deployments, or content restricted under Section 5.4. We are happy to review a draft for factual accuracy; review is optional and we will not use it to delay you beyond this Section 9.
9.4 If you and we cannot agree on disclosure timing, each side may act on its best judgment after the 90 day window; the safe harbor in Section 2 continues to apply to research that complied with this Policy, regardless of the disclosure disagreement.
10. Bounties
10.1 A paid bug bounty program is under evaluation and is not yet in effect. Any future program, its rewards, and its eligibility rules will be published at summerengine.com/legal/security or on a managed platform program page.
10.2 We may, at our discretion, offer thanks, swag, or discretionary rewards for exceptional reports before any formal program launches. No report creates an entitlement to payment unless and until a formal bounty program says so.
10.3 The authorization and safe harbor in Section 2 apply to Good-Faith Research whether or not any bounty program exists and whether or not any reward is paid.
11. Legal notes
11.1 This Policy is a statement of authorization and a set of commitments by Summer Labs, Inc.; it does not create a partnership, agency, or employment relationship, and it is not a contract for services.
11.2 If any part of this Policy conflicts with the Summer Games Terms of Service or other Additional Terms with respect to Good-Faith Research, this Policy controls to the extent of the conflict.
11.3 We may update this Policy at any time by posting a revised version with a new effective date at summerengine.com/legal/security. The version in effect when you began the specific research applies to that research.
11.4 Dispute resolution and governing law. Any Dispute between you and Summer arising out of or relating to this Vulnerability Disclosure Policy is governed by Section 23 (Dispute resolution and arbitration agreement) and Section 24 (Governing law and venue) of the Summer Games Terms of Service, which are incorporated into this Policy by reference and are not restated here. Those Sections include a mandatory informal resolution period, an agreement to individual arbitration for US Residents with a thirty (30) day right to opt out, a small claims option, a protocol for Coordinated Cases, and class action and jury trial waivers to the extent the law allows. Nothing in this Policy changes, restates, or adds to those Sections; if any text in this Policy appears to do so, Sections 23 and 24 of the Summer Games Terms of Service control. For a researcher who is not bound by the Summer Games Terms of Service, this Policy is governed by the laws of the State of California. Nothing in this Section 11.4 narrows the safe harbor in Section 2.