Security

Report a security vulnerability

If you believe you have found a security issue in EchoLab, tell us privately so we can investigate it responsibly.

Private reporting channel

Email [email protected]

Send sensitive reports only to this address. It routes to a monitored private inbox.

Start a private report

What this policy covers

This channel covers security vulnerabilities in the EchoLab apps for Fire TV, Android TV, Android, and iOS; the EchoLab account and API service at api.echolab.app; and the public product site at echolab.app.

For setup, billing, or general product help, use Support. For privacy or data-rights requests, use [email protected].

For automated discovery, see our security.txt record.

What to include

A clear report helps us reproduce and assess the issue. Include as much of the following as you can:

Do not include credentials, personal data, or other people's information unless it is essential to explain the issue. If a report needs a large or sensitive attachment, contact us first so we can agree a safe transfer method.

What happens next

  1. Report received Within 2 business days

    We acknowledge your report and confirm that it reached the right place.

  2. Initial assessment Within 5 business days

    We share an initial triage result or ask for the details needed to continue.

  3. While the report remains active At least every 10 business days

    We send a status update until the report is resolved or otherwise closed.

These are communication targets, not a fixed remediation deadline. Resolution time depends on severity, complexity, platform review, and the work needed to verify a safe fix.

Coordinated disclosure

This policy does not authorize you to test any system, account, or data that you do not own or have explicit permission to test. Make a good-faith effort to avoid privacy violations, data loss, and service disruption. Give us a reasonable opportunity to investigate and address the report before publishing details, and coordinate disclosure timing with us while the report is active.

Bounties and encrypted reports

EchoLab does not currently operate a paid bug-bounty programme. We do not currently publish a PGP key; if you need an encrypted transfer method, contact us first without including sensitive details.