Skip to content

Security

How to report a vulnerability in SINK, and what you can expect from us.

Scope

The disclosure scope is limited to these production surfaces:

  • https://sink.fm
  • https://api.sink.fm

Non-production and local environments, and third-party services not operated under the sink.fm domain, are out of scope unless a report shows direct impact on the production service.

Reporting

Report security issues by email. Include a clear description, the affected URL or feature, reproduction steps, an impact assessment, and anything needed to reproduce it.

Please do not publish details before we have had a reasonable opportunity to investigate and remediate.

Report security issues to security@sink.fm.

What to expect

  • We aim to acknowledge new reports within 3 business days.
  • We aim to keep you informed about triage status and remediation progress.
  • We credit you publicly after a fix ships, if you want that.

Safe harbor

We will not pursue action against good-faith research that:

  • avoids privacy violations, data destruction, and service disruption
  • does not use social engineering, phishing, or physical attacks
  • does not access, modify, or retain data beyond what is minimally necessary to demonstrate the issue
  • stops testing and reports promptly after confirming the issue

Encryption

No public PGP key is published at this time. If encrypted disclosure becomes available, this page and /.well-known/security.txt will be updated in the same change.