Skip to content

Security

How Bastion keeps you safe

A security bot has to be hard to attack too. Here's how Bastion protects your account and your server.

Last updated

Signing in

  • Discord sign-in only. There's no Bastion password to steal, reuse or leak.
  • Sessions are kept in our database, not in a token your browser holds. Signing out ends the session on our side too.
  • Discord tokens are encrypted at rest with AES-256-GCM.

The dashboard

  • Every request checks again. Each time you open or save a server's settings, Bastion checks with Discord that you still manage that server, and never relies on an answer more than a minute old. Lose the role, lose the access.
  • Protection settings are locked down. Anyone with Manage Server can open the dashboard, but only the server owner and people on the owner's trusted list can change Anti-Nuke, the Join Gate, Anti-Raid, Verification, Logs, Backups, moderator roles or the security level. Other admins can look at those pages but can't change them.
  • Only the owner picks trusted people. Other admins can see the trusted list but can't change it.
  • You're told when protection is weakened. If someone switches off Anti-Nuke, the Join Gate, Anti-Raid, Automod, the check on who adds bots or dangerous-permission blocking, removes the security alerts channel, or adds a trusted person, Bastion posts in the security alerts channel and messages the owner. The owner gets at most one message every 5 minutes.
  • A strict Content-Security-Policy. The site only runs its own scripts. It loads no outside scripts, fonts or frames.
  • Plans are enforced twice. Pro-only settings are checked when you save and again when the bot reads them.

Verification without the scams

Bastion verifies new members inside your server with a button and, if you choose, a short code shown as a picture. It never uses a QR code, and it never sends a direct message or a link to verify someone.

If a bot asks you to scan a QR code or sign in through a link in a direct message, it's trying to steal your account. It isn't Bastion. See how verification works.

Bot permissions

Bastion doesn't ask for Administrator. It asks only for the permissions it needs, and each one is explained.

See the full permission list and why each one is there.

What we store

Bastion never stores message content or passwords, and card details stay with Stripe. Message logs show the text of a deleted or edited message in your own Discord channel only, never in our database. The privacy policy has the full list.

Report a vulnerability

Found a security problem? Email support@bastionbot.xyz. Tell us what you found and how to reproduce it.

Please give us a chance to fix it before you share it publicly, and don't test on servers or accounts that aren't yours.