Compliance
Security & Responsible Disclosure
This page is maintained by The World of Greek Mythology to describe how we protect user data and how to report vulnerabilities. It is not an independent certification.
How we protect your data
- All traffic is served over HTTPS.
- Passwords are hashed by our authentication provider; we never see plaintext credentials.
- Our database uses row-level security so users can only read and write their own data.
- Administrative access is gated by role checks and multi-factor sign-in.
- Analytics data is stored without raw IP addresses; visitor identifiers rotate on ~13-month schedules.
- Media uploads live in a private bucket and are served through short-lived signed URLs.
Shared responsibility
Please protect your own account: use a unique password, keep your email address current, and sign out on shared devices.
Reporting a vulnerability
If you believe you have found a security issue, please email help@worldofgreekmythology.com with the subject line Security Report and include:
- A description of the issue and where you found it.
- Steps to reproduce, and any proof-of-concept.
- Your name / handle if you would like credit.
Good-faith safe harbor
We will not pursue legal action against researchers who: give us a reasonable time to investigate and fix before disclosing publicly; do not access user data beyond what is needed to demonstrate the issue; do not degrade the service for other users; and comply with all applicable laws.
Please do not: perform testing that affects other users' data, run automated scanners against the production site without prior arrangement, or exploit an issue beyond what is needed to demonstrate it.
