The world of Talam

Security

Talam welcomes good-faith reports that help protect players, accounts, update delivery, and multiplayer infrastructure.

Report privately

Email security@talamgame.com with a clear description, affected component, reproduction steps, potential impact, and only the minimum evidence needed. Remove passwords, tickets, private keys, personal data, and unrelated player information.

Safe research expectations

  • Do not access, modify, delete, or retain another person’s data.
  • Do not disrupt services, degrade availability, spam endpoints, or perform denial-of-service or load testing.
  • Do not use social engineering, phishing, malware, physical attacks, or attacks against third-party providers.
  • Do not test the live private Alpha beyond your own authorized account without written permission.
  • Stop when a vulnerability is confirmed and allow reasonable time for investigation and repair before disclosure.

Current scope

Potentially in scope: talamgame.com, the approved Talam launcher and client, authentication endpoints, signed update delivery, and game services operated by Talam. Third-party hosting, email, Discord, operating systems, and services not controlled by Talam are out of scope and should be reported to their owners.

Our commitment

We will acknowledge actionable reports when operationally possible, investigate in good faith, limit disclosure of reporter information, and communicate remediation status where appropriate. Talam does not currently operate a bug bounty or promise payment. This policy is not authorization for unlawful activity and cannot bind third parties or law enforcement.

Urgent issue: Put “URGENT SECURITY” in the subject line. Never send an active secret in ordinary email.