Responsible reporting

Security.

If you believe you found a vulnerability in GonzoArcade or a GonzoWorks game, report it privately so it can be investigated without putting players or systems at risk.

Updated August 26, 2026

How to report

Email aj@ajgonzo.com with “Security Report” in the subject. Identify the affected domain or game, describe the issue and impact, provide reproducible steps, and include only the minimum evidence needed. Do not include another person’s personal data.

Testing boundaries

Good-faith testing must avoid harm. Do not access, change, retain, or disclose data that is not yours; disrupt service; degrade performance; use social engineering; send spam; test third-party providers such as PayPal or Authentik; evade authentication; deploy malware; perform denial-of-service testing; or use automated scanning that creates significant traffic. Stop immediately if you encounter sensitive information and report what happened.

Scope

This channel covers the GonzoArcade portal and games operated by GonzoWorks on ajgonzo.com domains. Third-party services, infrastructure not controlled by GonzoWorks, and unrelated personal or business systems are out of scope. If you are unsure, ask before testing.

What to expect

We will make a reasonable effort to acknowledge a useful report, investigate, and communicate material status. Response time depends on severity and project availability. Please allow time to fix a confirmed issue before publishing details.

There is no bug-bounty program and no promise of payment, reward, credit, or legal safe harbor. Authorization is limited to testing that stays within this published scope, these boundaries, and applicable law.

Player security

Use unique passwords where a specific game offers accounts, keep your browser updated, do not reuse credentials, and verify that you are on the expected ajgonzo.com hostname before entering information. GonzoWorks will not ask for your password by email.