Skip to content

Security: halfofsever/ValoranTools.gg

Security

SECURITY.md

Security Policy | 安全政策

Our Commitment to Safety / 我们的安全承诺

At ValoranTools.gg, account security and user privacy are not just features—they are the foundation of our project. As an independent tool for the global Valorant community, we implement a "Privacy-First" architecture to ensure zero risk to your Riot Games account. 在 ValoranTools.gg,账号安全与用户隐私不仅是功能,更是项目的基石。作为面向全球社区的独立工具,我们采用“隐私至上”的架构,确保您的 Riot 账号零风险。


1. Authentication Architecture / 身份验证架构

🔑 Official Riot Sign-On (RSO) / 官方 RSO 集成

  • EN: We strictly use the official Riot Sign-On (RSO) system. Your login process happens entirely on Riot's official servers.
  • CN: 我们严格使用官方 RSO 登录系统。您的登录过程完全在 Riot 官方服务器上完成。
  • EN: WE NEVER see, collect, or store your Riot password.
  • CN: 我们绝不接触、收集或存储您的 Riot 账号密码。

🔒 Non-Custodial Data / 非托管数据处理

  • EN: Any sensitive tokens required for shop tracking are processed via secure, transient sessions.
  • CN: 商店追踪所需的敏感 Token 仅通过加密的瞬时会话处理。
  • EN: We do not maintain a database of user credentials. Your data stays with you and Riot Games.
  • CN: 我们不维护用户凭据数据库。您的数据始终属于您自己和官方。

2. Compliance & Anti-Cheat / 合规性与反作弊声明

  • EN: ValoranTools.gg is a web-based companion. It DOES NOT interact with game memory or modify local game files.
  • CN: ValoranTools.gg 是一个基于 Web 的辅助工具。它不会读取游戏内存,也不会修改本地游戏文件。
  • EN: Using our tools is fully compliant with Riot Games' Developer Policies and does not trigger any anti-cheat (Vanguard) flags.
  • CN: 使用我们的工具完全符合 Riot Games 开发者政策,不会触发任何反作弊(Vanguard)机制。

3. Reporting a Vulnerability / 漏洞报告

If you discover a security vulnerability, please help us keep the community safe by reporting it responsibly. 如果您发现了安全漏洞,请通过以下渠道联系我们,共同维护社区安全:

  • Contact / 联系方式: [Your Discord / Contact Info]
  • Response Time / 响应时间: We aim to respond within 48 hours.

⚠️ Disclaimer / 免责声明

ValoranTools.gg is an independent project and is not endorsed by or affiliated with Riot Games. ValoranTools.gg 是一个独立项目,未获得 Riot Games 的背书,亦不隶属于 Riot Games。

There aren’t any published security advisories