Report a security vulnerability
If you believe you have found a security issue in EchoLab, tell us privately so we can investigate it responsibly.
Email [email protected]
Send sensitive reports only to this address. It routes to a monitored private inbox.
Start a private reportWhat this policy covers
This channel covers security vulnerabilities in the EchoLab apps for Fire TV, Android TV, Android, and iOS; the EchoLab account and API service at api.echolab.app; and the public product site at echolab.app.
For setup, billing, or general product help, use Support. For privacy or data-rights requests, use [email protected].
For automated discovery, see our security.txt record.
What to include
A clear report helps us reproduce and assess the issue. Include as much of the following as you can:
- the affected app, service, URL, version, and device or operating system;
- steps to reproduce the behaviour and what you expected instead;
- the security impact and who or what could be affected;
- supporting logs, screenshots, or a minimal proof of concept; and
- a safe way to contact you with follow-up questions.
Do not include credentials, personal data, or other people's information unless it is essential to explain the issue. If a report needs a large or sensitive attachment, contact us first so we can agree a safe transfer method.
What happens next
-
Report received
Within 2 business days
We acknowledge your report and confirm that it reached the right place.
-
Initial assessment
Within 5 business days
We share an initial triage result or ask for the details needed to continue.
-
While the report remains active At least every 10 business days
We send a status update until the report is resolved or otherwise closed.
These are communication targets, not a fixed remediation deadline. Resolution time depends on severity, complexity, platform review, and the work needed to verify a safe fix.
Coordinated disclosure
This policy does not authorize you to test any system, account, or data that you do not own or have explicit permission to test. Make a good-faith effort to avoid privacy violations, data loss, and service disruption. Give us a reasonable opportunity to investigate and address the report before publishing details, and coordinate disclosure timing with us while the report is active.
Bounties and encrypted reports
EchoLab does not currently operate a paid bug-bounty programme. We do not currently publish a PGP key; if you need an encrypted transfer method, contact us first without including sensitive details.