Security
How to report a vulnerability in SINK, and what you can expect from us.
Scope
The disclosure scope is limited to these production surfaces:
https://sink.fmhttps://api.sink.fm
Non-production and local environments, and third-party services not operated under the sink.fm domain, are out of scope unless a report shows direct impact on the production service.
Reporting
Report security issues by email. Include a clear description, the affected URL or feature, reproduction steps, an impact assessment, and anything needed to reproduce it.
Please do not publish details before we have had a reasonable opportunity to investigate and remediate.
Report security issues to security@sink.fm.
What to expect
- We aim to acknowledge new reports within 3 business days.
- We aim to keep you informed about triage status and remediation progress.
- We credit you publicly after a fix ships, if you want that.
Safe harbor
We will not pursue action against good-faith research that:
- avoids privacy violations, data destruction, and service disruption
- does not use social engineering, phishing, or physical attacks
- does not access, modify, or retain data beyond what is minimally necessary to demonstrate the issue
- stops testing and reports promptly after confirming the issue
Encryption
No public PGP key is published at this time. If encrypted disclosure becomes available, this page and /.well-known/security.txt will be updated in the same change.
