Security
Found a vulnerability? Report it to [email protected] and we will not take legal action against you for the research that found it.
We answer within 72 hours, keep you informed until it is fixed, and credit you publicly if you want the credit.
Reporting a vulnerability
Email [email protected]. Include what you found, how to reproduce it, and what an attacker could do with it. A rough email beats a polished one that never gets sent.
You do not need an account, you do not need to identify yourself, and you do not need to ask permission first.
Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you, and we will not report you for the research that found the issue.
This holds even if you were mistaken, and even if you found the problem while doing something we would rather you had not done, so long as you stopped at the point described below and told us about it.
If someone else brings a legal claim against you for research conducted under this policy, tell us and we will make it publicly known that your work was authorised.
What we ask
- Stop at proof. Once you can show a problem exists, stop. Do not read, copy, keep or share anyone's music or personal data.
- Use your own account. Create a second one if you need two. Do not touch another artist's catalogue.
- Nothing destructive. No denial of service, no load testing, no deleting or altering data that is not yours.
- People are out of scope. No phishing our staff, no social engineering, no physical access attempts.
- Give us time. 90 days before publishing, or sooner if we have fixed it and agreed. If we go quiet on you, publish. That would be our failure, not yours.
What we commit to
- An acknowledgement from a person, not an autoresponder, within 72 hours.
- An assessment and a plan within 7 days.
- Critical issues fixed within 7 days, high within 30, everything else on a timeline we tell you.
- Updates as we go, rather than silence until it is closed.
- Public credit on this page if you want it, and no mention of you at all if you do not.
We are a small company and cannot yet offer a cash bounty. We will say so honestly rather than dangle one. What we can offer is a fast, respectful process and credit that is actually visible.
Where the risk actually is
Worth being straight about, because it changes what you should worry about.
The realistic threat to unreleased music is almost never someone breaking into a company. It is a person you sent it to. A demo forwarded to a friend, a link posted in a group chat, a laptop left open at a label.
That is why sharing here is built the way it is. Every link is separate and can be killed on its own without touching the others, download is off unless you turn it on, links can carry a passcode, an expiry or a view limit, and you can see who opened one. If something does leak, you have a much shorter list of people to ask.
What we do about the rest
Without going into how any of it is built:
- Everything is encrypted in transit and at rest.
- Your masters are never the file anyone streams, and the parts of the system that serve public pages have no route to them.
- There is no browse page and no discovery feed. Not a setting that is switched off. It does not exist, so there is nothing to enumerate.
- We never receive your card number. Payment details go to our merchant of record and never reach us.
- Passwords are stored only as hashes. Nobody here can read one, including us.
- Staff access to production is limited, individually identified and logged.
- We do not scan, analyse or train on your music, and we do not sell data to anybody.
If something goes wrong
If a breach affects your data we will tell you within 72 hours of confirming it, and we will tell you what we know at that point rather than waiting until the story is tidy. That includes saying that we do not yet know something.
Regulators will be notified where the law requires it. We will publish a write up afterwards.
Credit
Nobody has reported an issue yet. When somebody does, and wants to be named, they will be listed here.
Anything else
For account problems rather than vulnerabilities, use [email protected]. For abuse, [email protected].