Skip to content

Security

Melosome designs systems with the expectation that errors, misuse, dependency failures and hostile activity are possible.

Security therefore includes prevention, detection, containment, evidence and recovery.

Our approach

Controls are selected according to the service, data, users, environment and consequence of failure. The engineering standard covers:

  • identity and access management;
  • least privilege;
  • separation of environments and duties where appropriate;
  • encryption in transit and protection of stored sensitive data;
  • secure configuration and secret management;
  • software dependency and supply-chain awareness;
  • peer review and testing;
  • logging and monitoring;
  • vulnerability management;
  • backup, restoration and continuity;
  • incident response; and
  • secure change and retirement.

What we do not claim

No responsible organisation can promise that a system is invulnerable.

Melosome does not use phrases such as “unbreakable security” or treat a certification, cloud provider or technology choice as proof that risk has been eliminated.

Reporting a vulnerability

Email:

info@melosome.app

Subject:

[SECURITY] Vulnerability report

Include enough detail for us to understand and reproduce the issue. Do not include unnecessary personal data or data taken from other users.

Responsible disclosure

Researchers must read and follow the Responsible Vulnerability Disclosure Policy.

The policy allows good-faith reporting within defined boundaries. It does not grant permission for denial of service, social engineering, physical access, privacy intrusion, data exfiltration, destructive activity or testing of third-party systems.

Security.txt

A machine-readable contact file is published at:

/.well-known/security.txt

Service-specific information

The corporate website trust page is not a substitute for product-specific assurance.

As products are released, their security model, data processing, support and disclosure information will be published separately where appropriate.

Responsible Vulnerability Disclosure Policy

Effective date: 2 August 2026

1. Purpose

Melosome Group Ltd welcomes good-faith reports that help protect Melosome systems and users.

This policy explains how to report a suspected vulnerability and the boundaries for research.

It is not a bug-bounty programme and does not promise payment.

2. Contact

Email:

info@melosome.app

Subject:

[SECURITY] Vulnerability report

Do not send vulnerability detail through public social media.

3. What to include

Provide, where available:

  • the affected domain, page, endpoint, asset or component;
  • a concise description of the issue;
  • the conditions required to reproduce it;
  • clear reproduction steps;
  • the observed and expected behaviour;
  • likely impact;
  • screenshots, request examples or proof-of-concept material that does not expose third-party data;
  • whether any data was accessed, altered or retained;
  • your name or preferred attribution, if any; and
  • a secure way to contact you if ordinary email is unsuitable.

Do not include malware, live credentials, private keys or unnecessary personal data.

4. Good-faith expectations

To remain within this policy, you must:

  • act to protect users and data;
  • stop when you encounter personal, confidential or third-party information;
  • access only the minimum information required to demonstrate the issue;
  • avoid changing or deleting data;
  • avoid creating persistence;
  • avoid disruption or degradation;
  • report promptly;
  • keep the issue confidential while we investigate; and
  • comply with applicable law.

5. Out-of-scope activity

This policy does not authorise:

  • denial-of-service or resource-exhaustion testing;
  • destructive or disruptive activity;
  • social engineering, phishing or impersonation;
  • physical security testing;
  • testing employees' or suppliers' personal devices or accounts;
  • automated high-volume scanning;
  • credential stuffing or password spraying;
  • accessing another person's account or data;
  • exfiltrating, downloading or retaining unnecessary data;
  • planting malware, backdoors or persistent access;
  • attacks against third-party services or infrastructure;
  • testing a Melosome venture that publishes its own security policy outside that policy;
  • public disclosure before a coordinated disclosure date; or
  • any activity that would create a material safety, privacy, financial or operational risk.

If safe validation is not possible within these limits, report the suspected issue without further testing.

6. Safe-harbour intention

Where you act in good faith, comply with this policy and make a reasonable effort to avoid harm, Melosome does not intend to initiate legal action against you for the authorised research described here.

This statement:

  • does not authorise unlawful conduct;
  • does not bind third parties;
  • does not waive Melosome's rights in cases of bad faith, harm, coercion, extortion or policy breach; and
  • is not a guarantee of immunity from action by another person or authority.

If you are uncertain whether an action is permitted, ask before proceeding.

7. Our response targets

We aim to:

  • acknowledge a credible report within five working days;
  • provide an initial triage response within ten working days;
  • maintain reasonable communication while the issue is active; and
  • coordinate disclosure after remediation where public disclosure is appropriate.

These are targets, not service-level guarantees. Complex or third-party-dependent issues may take longer.

8. Disclosure

Do not disclose the vulnerability publicly until:

  • Melosome confirms remediation;
  • a disclosure date is agreed; or
  • a reasonable period has passed and you have made a genuine effort to coordinate with us.

We will consider the severity, user risk, remediation complexity, dependency ownership and need for users to take action.

9. Recognition and rewards

Melosome may, at its discretion and with your agreement, acknowledge a valuable report.

No payment, reward, employment, contract or public recognition is promised unless agreed in writing.

10. Privacy

Information submitted in a report will be used to investigate, remediate, communicate and preserve appropriate security records.

See the Privacy Policy.

11. Changes

We may update this policy. The current published version applies at the time of testing.