Security

Last updated 3 August 2026

In short

Found a vulnerability? Report it to [email protected] and we will not take legal action against you for the research that found it.

We answer within 72 hours, keep you informed until it is fixed, and credit you publicly if you want the credit.

Reporting a vulnerability

Email [email protected]. Include what you found, how to reproduce it, and what an attacker could do with it. A rough email beats a polished one that never gets sent.

You do not need an account, you do not need to identify yourself, and you do not need to ask permission first.

Safe harbour

If you follow this policy in good faith, we will not pursue or support legal action against you, and we will not report you for the research that found the issue.

This holds even if you were mistaken, and even if you found the problem while doing something we would rather you had not done, so long as you stopped at the point described below and told us about it.

If someone else brings a legal claim against you for research conducted under this policy, tell us and we will make it publicly known that your work was authorised.

What we ask

What we commit to

We are a small company and cannot yet offer a cash bounty. We will say so honestly rather than dangle one. What we can offer is a fast, respectful process and credit that is actually visible.

Where the risk actually is

Worth being straight about, because it changes what you should worry about.

The realistic threat to unreleased music is almost never someone breaking into a company. It is a person you sent it to. A demo forwarded to a friend, a link posted in a group chat, a laptop left open at a label.

That is why sharing here is built the way it is. Every link is separate and can be killed on its own without touching the others, download is off unless you turn it on, links can carry a passcode, an expiry or a view limit, and you can see who opened one. If something does leak, you have a much shorter list of people to ask.

What we do about the rest

Without going into how any of it is built:

If something goes wrong

If a breach affects your data we will tell you within 72 hours of confirming it, and we will tell you what we know at that point rather than waiting until the story is tidy. That includes saying that we do not yet know something.

Regulators will be notified where the law requires it. We will publish a write up afterwards.

Credit

Nobody has reported an issue yet. When somebody does, and wants to be named, they will be listed here.

Anything else

For account problems rather than vulnerabilities, use [email protected]. For abuse, [email protected].