Skip to content

Security: sraphaz/soundscape

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for security problems.

Email or privately message the maintainers, or use GitHub’s private vulnerability reporting if enabled on this repository.

Include:

  • Description of the issue
  • Steps to reproduce
  • Impact (especially around audio privacy, location, or API abuse)

Audio & location

Soundscape handles environmental audio and geospatial data. Treat both as sensitive:

  • Prefer on-device or consented upload flows
  • Avoid long retention of identifiable speech when the goal is bioacoustics
  • Rate-limit and authenticate write endpoints before production

There aren't any published security advisories