| Version | Supported |
|---|---|
| Latest release | Yes |
| Previous release | Security fixes only |
| Older versions | No |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
Email: support@lotraom.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Timeline: Depends on severity, typically 30-90 days
- Please give us reasonable time to address the issue before public disclosure
- We will credit reporters in release notes (unless you prefer anonymity)
- We do not offer bug bounties at this time
- Download LOTRAOM only from official sources (GitHub releases, official launcher)
- Keep your game and mod updated to the latest version
- Report suspicious behavior or files
- Never commit secrets, API keys, or credentials
- Use environment variables or secure configuration for sensitive data
- Follow the security guidelines in security.md
This policy covers:
- LOTRAOM mod (
/Main/,/ModuleData/) - LOTRAOM Launcher (
/launcher/) - Update Server (
/launcher/server/) - Analytics infrastructure (
/devops/analytics/)
For security concerns: support@lotraom.com
For general questions: Use GitHub Issues or Discord