Skip to content
Staffly
FeaturesHow it worksFAQ
Sign inGet started

Security

Last updated: July 25, 2026

How we protect your data

  • Passwords are hashed with scrypt and a random salt per account — never stored or logged in plain text.
  • Sessions are signed (HMAC) so they can't be tampered with client-side.
  • All traffic is served over HTTPS.
  • Discord and Roblox client secrets are stored server-side only, as environment variables — never shipped to the browser.
  • Database access runs through server-side functions with credentials that are never exposed to the client.

Responsible disclosure

If you believe you've found a security vulnerability in Staffly, please report it privately before disclosing it publicly, so we have a chance to fix it first.

  • Report to: security@staffly.app
  • Please include: steps to reproduce, affected URL(s), and impact if known.
  • What to expect: we'll acknowledge reports as quickly as we reasonably can and keep you updated as we investigate.

We won't take legal action against good-faith security research that follows this process and doesn't access, modify, or exfiltrate other users' data.

Scope

This covers Staffly's own web application and API. Vulnerabilities in Discord's or Roblox's own platforms should be reported directly to them.

© 2026 Staffly. Not affiliated with Discord or Roblox.
PrivacyTermsCookiesAccessibilitySecurity