Stoatmod / Security and trust

Security and operational safeguards

Security depends on permission boundaries, private access, honest failure reporting and verification of the real server state—not on hiding an inaccurate success behind a log entry.

Return home

About the service

Understand Stoatmod dashboard access, permission boundaries, outcome verification, fail-open moderation and responsible security reporting.

  • Reviewed 31 August 2026
  • 4 sections
  • Trust

Dashboard access

  • Access is limited to the server owner, Manage Server members and explicit owner grants.
  • Login codes are single-use and expire after ten minutes.
  • Dashboard sessions last 12 hours.
  • Owners can revoke access and invalidate sessions.
  • Private routes are excluded from search indexing and public sitemaps.

Moderation safeguards

  • The default content threshold is 90%.
  • Observe and review modes support testing before enforcement.
  • Provider failures leave content in place instead of silently deleting it.
  • Suicidal-thoughts matches send support DMs without deleting messages or adding warnings.
  • Serious actions should be verified against the member or message state in Stoat.

Known boundaries

Role hierarchy and channel permissions can prevent an otherwise valid action. External Stoat events may not always identify the acting moderator. Automatic reversal after an accepted appeal can fail when permission or server state has changed. Documentation describes these boundaries so teams can plan recovery.

Report a security concern

Send a concise report to admin@modstoat.site with the affected public URL or feature, time in UTC, reproducible steps and impact. Do not include credentials, active tokens or unrelated personal information. Use the private global-report workflow for user safety and platform-abuse reports rather than publishing evidence.

Ready to configure a server?

Install Stoatmod, then verify the first outcome.

Open the official bot profile →