Effective Date: July 13, 2026
At STHAN™ Music, we take the security of our website, services, and user information seriously. If you discover a security vulnerability or believe you have found a security issue affecting our website, we encourage you to report it responsibly.
We appreciate the efforts of security researchers and members of the community who help us improve the security of our platform.
1. What to Report
You may report security issues including, but not limited to:
- Unauthorized access vulnerabilities
- Authentication or login issues
- Cross-Site Scripting (XSS)
- SQL Injection
- Cross-Site Request Forgery (CSRF)
- Remote Code Execution (RCE)
- Security misconfigurations
- Broken access controls
- Sensitive data exposure
- Other vulnerabilities that may affect the security of our website or users
2. Responsible Disclosure Guidelines
When reporting a security issue, we kindly ask that you:
- Act in good faith and avoid violating the privacy of our users.
- Do not exploit the vulnerability beyond what is necessary to demonstrate its existence.
- Do not access, modify, copy, or delete data belonging to others.
- Do not interrupt or degrade our website or services.
- Provide sufficient information so we can reproduce and investigate the issue.
- Allow us reasonable time to investigate and resolve the issue before publicly disclosing it.
3. Information to Include
To help us investigate your report efficiently, please include:
- A detailed description of the vulnerability.
- The affected page(s) or URL(s).
- Steps to reproduce the issue.
- Proof-of-concept (if available).
- Screenshots or screen recordings (if applicable).
- Your name and contact information for follow-up.
4. Our Commitment
Upon receiving a valid security report, we will make reasonable efforts to:
- Acknowledge receipt of your report.
- Review and investigate the reported issue.
- Take appropriate action to resolve confirmed vulnerabilities.
- Communicate with you regarding the status of the report when appropriate.
5. Scope
This page applies only to security vulnerabilities affecting the official STHAN™ Music website and related online services.
General customer support requests, copyright claims, business inquiries, or other non-security issues should be submitted through our regular contact channels.
6. No Bug Bounty Program
Unless explicitly announced by STHAN™ Music, we do not currently operate a bug bounty or vulnerability reward program.
Submitting a security report does not create any entitlement to financial compensation or other rewards.
7. Legal Protection
We will not pursue legal action against individuals who, in good faith, discover and responsibly disclose security vulnerabilities while complying with this policy and applicable laws.
8. Contact Us
To report a security issue, please contact us at:
STHAN™ Music
Website:
https://sthanmusic.com
Email:
security@sthanmusic.com
Please include the subject line: "Security Vulnerability Report" to help us process your report more efficiently.
We sincerely appreciate your efforts in helping us maintain the security, privacy, and reliability of STHAN™ Music.
