Security & Trust

Control should come with clear boundaries.

Kervak uses access controls, Discord identity checks, operational safeguards and privacy-minded defaults to reduce unnecessary exposure while keeping community administration practical.

◎

Discord identity & access

Community Control uses Discord OAuth for dashboard sign-in. The dashboard checks Kervak-installed servers and only presents eligible servers the signed-in account can manage.

⌘

Role-aware administration

Discord role hierarchy and configured Kervak roles are part of the authorization model. Sensitive management actions should remain limited to trusted staff.

◇

Secrets stay server-side

Bot credentials, SMTP passwords and other service secrets belong in Railway environment variables and are not embedded in public website JavaScript or HTML.

↺

Recovery tooling

Community Control includes configuration history, backups, snapshots and recovery-oriented tooling to reduce the impact of accidental administrative changes.

▣

Logging & accountability

Moderation records, audit-oriented systems and dedicated log destinations help authorized teams review actions and investigate operational issues.

●

Service visibility

The public website reports live Community Control health and Kervak maintains status/incident surfaces so availability problems can be identified separately from server configuration issues.

Data practices

Use only what the service needs.

Community owners remain responsible for their own Discord content, configuration, permissions and notices to members.

Customer and member data

Kervak processes information required for enabled features such as configuration, moderation records, tickets, applications, staff records, audit events and authorized administrator actions. Kervak's terms state that this data is not sold or used for targeted advertising.

Retention & exports

Transcript and backup retention varies by plan. Backups and snapshots support recovery, but important records should also be exported when a customer has longer-term retention requirements.

Responsible reporting

Found a security issue?

Do not publish exploit details in a public channel. Send a private report with the affected product, reproduction steps, impact and safe supporting information. Never send passwords, bot tokens, API keys or payment credentials.