Legal
Security
This page summarises the security principles and operational practices that guide how Bulwark is designed and run.
Last updated September 20, 2026
Purpose
Bulwark is designed to help Discord communities respond to a specific class of incident: coordinated scam floods in which a compromised account posts the same or substantially similar content across multiple channels in a short period. Our security posture emphasises rapid, reversible containment and preservation of evidence for human review.
Detection approach
Detection is based on deterministic matching of burst behaviour rather than open-ended content classification. Message content is fingerprinted so that near-duplicates may still be associated with a single incident, including where characters are substituted, spacing is padded, or similar obfuscation techniques are used.
Matching is evaluated across channels within a server. No detection system can identify every malicious message or avoid every false positive. Server operators remain responsible for reviewing automated outcomes.
Containment
Where configured to do so, Bulwark’s default containment action is a reversible timeout-style restriction rather than an irreversible ban. The intent is to reduce further spread while moderators assess the incident. Authorised server managers may disable detection using emergency controls if the Service behaves unexpectedly or if operational circumstances require it.
Evidence handling
When a burst is confirmed, Bulwark may retain associated links, transcripts, and attachments so that the incident remains reviewable after messages are deleted from Discord channels. Evidence is intended for the moderation and security workflows of the relevant server. Authorised managers may export available server-associated Bulwark data where export functionality is provided. Evidence should not be redistributed beyond what is reasonably necessary for legitimate investigation and enforcement within that community.
Access control
Management commands and sensitive views are intended for Discord guild managers and other operators who have been granted appropriate permissions. Server administrators should restrict who can alter Bulwark configuration, review incidents, or export data. Where available, audit logs record configuration changes and moderation actions performed through the Service.
Operational safeguards
We maintain safeguards appropriate to the nature of the Service, including:
- requesting Discord permissions that are reasonably necessary for advertised functionality;
- using logging and monitoring to investigate abuse, outages, and security events;
- limiting internal access to customer server data to personnel who need it for operations, support, or security; and
- applying ongoing hygiene to dependencies, hosting configuration, and related infrastructure as the Service evolves.
These measures are designed to reduce risk; they do not eliminate it. Absolute security cannot be guaranteed.
Shared responsibility
Security for a Discord community is a shared responsibility. Bulwark can improve response time for a particular attack pattern, but it does not replace Discord’s platform controls, role hygiene, member education, or moderator judgment. Operators should grant least-privilege access, review incidents promptly, and keep emergency disable procedures available to trusted staff.
Reporting a concern
If you believe you have identified a security vulnerability, suspected misuse of the Service, or another security-related concern, please contact legal@bulwarkbot.com. Include sufficient detail to allow us to reproduce and assess the issue. Please do not publicly disclose vulnerability details until we have had a reasonable opportunity to investigate and respond.
Updates
We may update this Security page as our practices and the Service change. The “Last updated” date reflects the most recent revision. For how we handle personal information more broadly, see our Privacy Policy.
