Skip to content

Security: bitcoin-corp/bitcoin-music

Security

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

The Bitcoin Corporation LTD. takes the security of Bitcoin Music seriously. We appreciate your efforts to responsibly disclose your findings.

How to Report

DO NOT create public GitHub issues for security vulnerabilities.

Please report security vulnerabilities by emailing:

What to Include

Please include the following in your report:

  • Type of issue (e.g., buffer overflow, SQL injection, XSS, etc.)
  • Full paths of source file(s) related to the issue
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue

Response Time

  • We will acknowledge receipt within 48 hours
  • We will provide a detailed response within 7 days
  • We will work on a fix and coordinate disclosure

Responsible Disclosure

We kindly ask that you:

  • Allow us reasonable time to fix the issue before public disclosure
  • Avoid exploiting the vulnerability beyond what's necessary for verification
  • Not access or modify user data without permission

Supported Versions

Version Supported
1.0.x
< 1.0

Security Best Practices

When using Bitcoin Music:

  • Keep your private keys secure
  • Never share your wallet seed phrase
  • Verify all transactions before signing
  • Use hardware wallets when possible
  • Keep your software updated

Legal

The Bitcoin Corporation LTD.
UK Company No. 16735102
Copyright (c) 2025 All Rights Reserved

There aren't any published security advisories