Back to the great hall

Security, Vulnerability Disclosure and Breach Notification Policy

The Watch on the Walls

How the House guards what you give it, and what it does when a wall is breached

Last sealed 3 August 2026

1. What is in place today

All traffic to and from the Site is encrypted in transit (TLS). Customer records are held in a managed database with row-level security, so one account cannot read another's data.

We never see or store full payment card numbers; card data is captured directly by our licensed payment gateway. We never receive or store identity-document images from our age-verification provider — only a pass or fail result.

Administrative powers are held by a single named officer of the House and are not delegated. Service credentials are stored as encrypted secrets, never in source code.

2. What is not yet in place — stated plainly

We would rather be honest than impressive. The following controls are planned and not yet operational: multi-factor authentication on customer accounts, third-party error-monitoring, and automated dependency vulnerability scanning in our build pipeline.

Until multi-factor authentication is live, we recommend a unique password for your account and we do not store anything in your account that could be used to make a purchase without a fresh payment authorisation.

This section will be amended, with a new date above, as each control goes live. If it still says this, it is still true.

3. Reporting a vulnerability

Send security reports to security@warbornblades.com. Include the affected URL or feature, the steps to reproduce, and the impact you believe it has.

We acknowledge every security report within 72 hours and give you a substantive assessment within 10 business days. We will tell you when it is fixed.

Safe harbour: if you act in good faith, stay within the scope of your own test accounts, do not access, alter, or exfiltrate another person's data, do not degrade the service, and give us reasonable time to remedy before disclosure, we will not pursue legal action against you and we will credit you if you wish.

Out of scope: denial-of-service, social engineering of our staff or suppliers, physical attacks, spam or rate-limit reports without demonstrated impact, and findings against third-party services we merely consume.

4. Incident response

On credible report or detection of a breach, the House follows a fixed order: contain, assess, notify, remedy, record.

Contain — affected credentials are rotated and, where necessary, the affected function is taken offline within 24 hours of confirmation. Assess — we determine what data was involved, whose, and for how long. Notify — see below. Remedy — the defect is fixed and the fix verified. Record — the incident, its timeline, and its cause are written to a permanent internal register.

5. Breach notification to you

If a breach affects your personal information and creates a risk to you, we will notify you by email without undue delay and in any event within 72 hours of our becoming aware of it, unless a law-enforcement authority instructs us in writing to delay.

The notice will state what happened, what categories of your data were involved, what we have done, what we advise you to do, and a direct address for questions.

We will notify supervisory authorities and state Attorneys General where the law requires it, within the periods those laws set — including the 72-hour period under the UK and EU GDPR and the applicable periods under United States state breach-notification statutes.

We will not conceal a breach, minimise it in the telling, or wait for it to become public before we speak.

Warborn Trial