Discord identity & access
Community Control uses Discord OAuth for dashboard sign-in. The dashboard checks Kervak-installed servers and only presents eligible servers the signed-in account can manage.
Security & Trust
Kervak uses access controls, Discord identity checks, operational safeguards and privacy-minded defaults to reduce unnecessary exposure while keeping community administration practical.
Community Control uses Discord OAuth for dashboard sign-in. The dashboard checks Kervak-installed servers and only presents eligible servers the signed-in account can manage.
Discord role hierarchy and configured Kervak roles are part of the authorization model. Sensitive management actions should remain limited to trusted staff.
Bot credentials, SMTP passwords and other service secrets belong in Railway environment variables and are not embedded in public website JavaScript or HTML.
Community Control includes configuration history, backups, snapshots and recovery-oriented tooling to reduce the impact of accidental administrative changes.
Moderation records, audit-oriented systems and dedicated log destinations help authorized teams review actions and investigate operational issues.
The public website reports live Community Control health and Kervak maintains status/incident surfaces so availability problems can be identified separately from server configuration issues.
Data practices
Community owners remain responsible for their own Discord content, configuration, permissions and notices to members.
Kervak processes information required for enabled features such as configuration, moderation records, tickets, applications, staff records, audit events and authorized administrator actions. Kervak's terms state that this data is not sold or used for targeted advertising.
Transcript and backup retention varies by plan. Backups and snapshots support recovery, but important records should also be exported when a customer has longer-term retention requirements.
Responsible reporting
Do not publish exploit details in a public channel. Send a private report with the affected product, reproduction steps, impact and safe supporting information. Never send passwords, bot tokens, API keys or payment credentials.
No security system is absolute. Kervak depends on third parties including Discord, Railway, Stripe and email infrastructure. Platform changes, outages and account compromise can affect service availability or security. Customers should protect administrator accounts with strong authentication and review server permissions regularly.