Found a vulnerability? Tell us first.
We ship in public. We disclose incidents in public. We’d rather patch a real vulnerability than read about it on Twitter. This page tells you how to bring one to us, what to expect after you do, and who’s gotten public credit for prior reports.
How to report
Email security@songforgeai.com with the subject line [VULN] followed by a short summary. Include:
- The class of issue (auth bypass / SSRF / IDOR / XSS / leakage / etc.)
- A reproduction path — specific URL, request body, expected vs actual response
- The earliest commit / build number where you can confirm the issue
- Your handle for credit attribution if accepted (or “anonymous” if you prefer)
Encryption is welcome but not required. PGP fingerprint will be published here once the operator’s key is rotated for security correspondence (target: end of 2026-Q2).
Response timeline
- Acknowledgement: 48 hours. We confirm receipt + triage priority.
- Initial assessment: 7 days. Reproduce or reject. If we can reproduce, we share a tentative severity rating and a target patch window.
- Patch + disclosure: target 30 days for critical, 90 days for medium / low. Critical issues land within 24 hours when feasible. Disclosure timing is coordinated with the reporter when reasonable; we won’t sit on something quietly for marketing reasons.
- Post-mortem: published. Like every other user-visible incident, security incidents get a public post-mortem at /incidents with root cause + prevention notes once the patch has shipped.
Safe-harbor commitment
Good-faith research conducted under this policy will not result in legal action from SongForgeAI. “Good faith” means:
- You report only what you found; you don’t exfiltrate user data beyond what proves the issue exists
- You give us a reasonable window to patch before public disclosure (see timeline above)
- You don’t use the issue to access other users’ songs, lyrics, or accounts
- You don’t run automated scans that materially degrade service for other users
This commitment applies to vulnerability research only — not terms-of-service violations (scraping, prompt injection at scale, rate-limit evasion).
Hall of fame
Researchers whose disclosures led to a shipped patch are credited here, with their permission. Categories:
- Critical — auth bypass, account takeover, secret leakage, RCE
- High — IDOR on private content, score-seal forgery, billing tampering
- Medium / low — XSS, CSRF gaps, information disclosure of non-sensitive data
No external reports yet. The B1817 reproducibility-seal incident (operator self-discovered + disclosed at /blog/we-claimed-signed- seals-for-390-builds) is the only public security-adjacent postmortem to date. The first external report accepted under this policy will be credited here with the discovery date + class.
What this policy does NOT cover
- Bug-bounty payouts. We do not currently run a paid bounty program. Triage capacity is the constraint; a real bounty requires staffing we don’t have. When that changes, this policy updates.
- Third-party services. Issues in Anthropic, OpenAI, Supabase, Stripe, Vercel, or Upstash should be reported to those vendors directly. We’ll coordinate disclosure if you cc us on a serious finding that affects our integration.
- Best-practice opinions. “You should use a different framework / hosting / database” isn’t a vulnerability report. Specific exploitable issues with concrete reproduction steps are.