Vulnerability Disclosure Policy
Effective date: September 9, 2026
In short: If you find a security flaw in Tonamorph, tell us at security@tonamorph.com and we will not take legal action against you for finding it. We answer within three business days, tell you what we found within ten, and keep you informed until it is fixed. You keep the right to publish: ninety days after you report, or as soon as we ship the fix, whichever comes first. We do not pay bounties — we are a very small team and would rather promise nothing than promise money we cannot pay — but we will credit you by name if you want that.
1. Who this is for
Anyone who finds a security weakness in Tonamorph — a security researcher, a customer, a passer-by. You do not need an account, an invitation or a prior relationship with us. You do not need to agree to anything before reporting.
This policy is published by Tonamorph Audio and covers the systems listed in section 3.
2. How to report
Email security@tonamorph.com. A machine-readable copy of this address is published at https://tonamorph.com/.well-known/security.txt (RFC 9116).
A useful report contains:
- what the weakness is, and which host, endpoint or plugin version it is in;
- the steps to reproduce it, ideally with the exact requests;
- what an attacker could do with it — the impact matters more than the class;
- any account, order or job identifiers you own that were involved;
- how you would like to be credited, or that you would rather not be.
Write in English, Hebrew or Russian. Screenshots and short videos are welcome; please do not attach whole database dumps or other people's data (see section 4).
If the finding is serious enough that plain email worries you, say so in a one-line message with no details, and we will agree an encrypted channel with you before you send anything.
3. Scope
In scope
| System | What it is |
|---|---|
https://tonamorph.com | The website, the account portal and the sign-in flow |
| The public API | The job, credit and account endpoints the plugin and the site call |
| The Tonamorph plugin (VST3/AU) | The released builds: their authentication, device pairing, update check and local storage |
| Our released installers | Their signatures, and the update channel that delivers them |
Out of scope
- Denial of service of any kind, volumetric testing, and anything that degrades the service for other people. We are a small service; a load test is indistinguishable from an outage.
- Social engineering of us, our users or our suppliers, and anything involving physical access.
- Third-party services we do not control — our database and authentication provider, our merchant of record, our email sender, our hosting and CDN. Report those to the provider; if their flaw affects our users, tell us as well and we will chase it.
- Reports with no demonstrated security impact: missing security headers on pages that carry nothing, mail-configuration opinions (SPF, DMARC, DKIM) absent a working spoof, version numbers, self-XSS, clickjacking on pages with no state-changing action, and unedited output from an automated scanner.
- Anything that requires an already-compromised device or a physically present attacker with the victim's unlocked machine.
If you are unsure whether something is in scope, report it. We would rather read one report too many.
4. What we ask while you research
- Use your own account and your own audio. Do not access, modify or download any data that is not yours. If you stumble into someone else's data, stop, do not save it, and tell us in the report.
- Stop at proof. Once you can demonstrate the weakness, stop. Do not escalate, pivot, plant a backdoor, or keep access.
- Do not exfiltrate. A screenshot of one record proving access is proof; a dump of the table is not, and it turns a research finding into a data breach that we would then have to notify.
- Do not degrade the service. No brute force, no fuzzing at volume, no spam to real users.
- Keep it to yourself while we fix it, on the timetable in section 6 — which is a deadline, not a gag.
5. Safe harbour
If you follow section 4 and stay within section 3, then as far as Tonamorph Audio is concerned:
- your research is authorised, and we will not report you to the authorities or bring a civil claim against you for it;
- we will not treat it as a breach of our Terms of Service or our End-User Licence Agreement, and the anti-circumvention and no-reverse-engineering clauses in those documents do not apply to work done under this policy;
- if a third party brings a claim against you for research that complied with this policy, we will make it publicly known that the work was authorised.
We cannot grant authorisation we do not hold: this safe harbour does not cover our suppliers' systems (section 3), and it cannot displace a law that applies to you regardless of our consent. If a legal process compels us to identify you, we will tell you before we comply, unless we are forbidden to.
Acting in good faith and telling us promptly is what this section protects. Extortion is not research: a message that withholds details pending payment ends the safe harbour.
6. What you get back from us
| Step | When |
|---|---|
| We confirm we received your report | 3 business days |
| We tell you whether we could reproduce it, and our assessment of severity | 10 business days |
| We keep you updated while it is open | at least every 14 days |
| We tell you it is fixed, and what we changed | on release |
You may publish ninety days after you reported, or as soon as the fix is released, whichever is earlier. If the fix will genuinely take longer, we will ask you — and you are free to say no. We will not ask you to sign a non-disclosure agreement as a condition of us fixing our own software.
Credit. With your permission we will name you in the release notes and in a public acknowledgements list. You choose the name and whether to include a link. You may decline; you may also change your mind later.
No bounty. We do not run a paid bug-bounty programme, and we would rather say so plainly than advertise one we cannot fund. If that changes, this page changes with it.
Your finding stays yours. We claim no rights in your report, your tooling or any suggestion you make in it, beyond the permission to use what you tell us to fix our own product and to describe the fix.
7. If user data was affected
If your report shows that personal data was or could have been exposed, we handle it under the breach procedure in our Privacy Policy — which includes notifying the supervisory authority and, where required, the people affected, within the statutory deadlines. Your report is what starts that clock, so the timestamp on your email matters; we record it.
8. This is not the address for other things
- Copyright complaints about audio go to the notice route in our Copyright Policy.
- Privacy requests about your own data (access, deletion, export) go to the address in our Privacy Policy.
- Refunds, billing and a job that produced bad stems go to support — see the Refund Policy.
- Account recovery is on the sign-in page. We will never ask you for your password, and we cannot read it.
9. Changes
We may update this policy. The version that applies to your report is the one published when you sent it; we keep the previous versions and will show you the one you relied on if it ever matters.
10. Contact
Tonamorph Audio
Security: security@tonamorph.com · Legal notices: support@tonamorph.com