Trust centre

Security practices

How Stew-Bot is designed to protect subscriptions, league records, Discord interactions and operational access.

Owner: Wade GeorgesonLast updated: 1 August 2026
Pre-launch policy draftBusiness registration details, a public support address and final legal review must be completed before paid public launch.
01

Security model

Stew-Bot is provided as a hosted service. Customers invite the Discord bot; they do not receive server credentials or the Python source. Public endpoints are intended to use TLS, restricted network paths and least-privilege service accounts.

02

Customer separation

Records are scoped to the relevant Discord server and league. Subscription entitlements are checked across commands, buttons, dropdowns and modal submissions, and unknown subscription states fail closed.

03

Discord access

Discord permissions and configured steward roles determine who can report, review, decide and administer the service. Billing actions are restricted to the server owner or members with Manage Server permission.

04

Payments and webhooks

Stripe handles card information. Stew-Bot is designed to retain subscription identifiers and status, not complete card numbers. Webhook signatures and duplicate-event controls are used before subscription state changes are accepted.

05

Secrets, logs and backups

Bot tokens, Stripe secrets and similar credentials belong in protected environment configuration, not source code or Discord messages. Operational logs, audit records and backups are restricted to authorised administration and retained only as necessary.

06

Customer responsibilities

  • Protect administrator and steward accounts with strong authentication.
  • Grant the bot only the Discord permissions required for its configured channels.
  • Do not place passwords, tokens, card numbers or unnecessary sensitive information in incident records.
  • Remove access promptly when staff roles change.
  • Export records required under league rules before cancellation or deletion.
07

Security incidents

Suspected compromise may result in credential rotation, temporary access restriction, log review, customer notification and other containment measures. Report suspected vulnerabilities privately through the official support pathway and do not publicly disclose exploit details before they can be addressed.