VYNLT

Security

Unreleased means unreleased.

What VYNLT does to protect music before release, stated precisely. If a claim on this page isn’t specific, it isn’t here.

01

Signing in

Passwords
Hashed with argon2id (19 MiB memory, 2 iterations). 10 to 256 characters. After 10 wrong attempts the account locks for 15 minutes, doubling up to 24 hours, and the owner is alerted. Unknown emails take the same time to reject as known ones.
Two-factor
Authenticator-app codes (TOTP, RFC 6238). A code can be used once: replays are rejected. The secret is encrypted with AES-256-GCM before it is stored.
Recovery codes
10 single-use codes, shown once, stored only as keyed hashes. Using one sends a security alert.
Passkeys and security keys
WebAuthn passkeys (Face ID, Touch ID, Windows Hello, Android) and hardware security keys, as a second factor or to sign in without a password. They are bound to the real site, so a look-alike page can’t use them.
Password reset
A single-use link valid for one hour. Reset signs out every session. Two-factor stays on after a reset, so access to your email alone is not enough.

02

Sessions and devices

Short-lived access
Access tokens last 15 minutes and are checked against the live session on every request, so signing a device out takes effect immediately.
Refresh tokens
Rotated on every use. If an old one is presented again, the whole session is revoked and you are notified. In the browser it lives in an httpOnly, SameSite=Strict cookie.
Devices
Every signed-in device by name, city and last use, with Sign out beside each, plus sign out everywhere. Changing your password signs out every other session.
Confirm it’s you
Sensitive actions need a fresh confirmation (step-up) within the last 10 minutes; an organization can shorten this to 60 seconds. With two-factor on, a password alone is not accepted.

03

What needs a fresh confirmation

Account security
Turning two-factor on or off, adding or removing a passkey, new recovery codes, changing password or email.
Downloadable links
Creating a share link that allows downloading originals.
Bulk copies
Connecting an external cloud, creating a backup target, starting a restore, and adding projects to a computer’s sync.
Destructive actions
Permanently deleting a project, song, version or file (which also requires archiving first and an admin role).
Organization control
Changing the security policy, transferring ownership, granting the owner role, deleting a workspace.

04

Organization policy

Require two-factor
An organization can require two-factor for every member. Members without it can’t open anything in the organization until they set it up, and admins see who is compliant.
Phishing-resistant admins
An organization can require admins and owners to be signed in with a passkey or security key before they manage members, settings, security or deletions.
Roles
Seven roles from Listener to Owner, inherited from organization to workspace to project. Nobody can grant a role higher than their own.

05

Access to music

Private by default
A song is visible only to people with a role on it. Without one, it returns “not found”, so its existence isn’t disclosed.
Checked on the server
Every request is authorized on the server against the role model. Hiding a button in the interface is convenience, not security.
Uploaders can’t download
Contributors who add versions don’t automatically get the originals of everyone else’s work.
Signed, short-lived media URLs
Audio is served through signed links that expire: 5 minutes for downloads, at most 30 minutes for streams. Each signature covers one file, its expiry and its type.
Safe file serving
Only audio, images and JSON play or display in the browser. Everything else is downloaded, never rendered, with a sandboxing content-security policy.

06

Share links

Stream-only by default
Recipients hear a streaming copy (AAC or Opus), never the original, unless downloads are switched on for that link.
Who can open a link
Only the people it names, signed in to an account with that address. There is no anonymous access to a link: no playback, downloads, notes or Listening Room seat without an account. Recipients get access to that link only, never to your workspace.
Controls per link
Password (locked for 15 minutes after 10 wrong guesses, with an alert to you), expiry date and view limit. Revoking or expiring a link ends access on the next request.
Revocable
Revoke a link at any time. A link also stops working if the person who created it loses access.
Stored safely
Only a keyed hash of each link token is stored. Every open and download is recorded.

07

Data at rest and in transit

In transit
HTTPS everywhere, with HTTP Strict Transport Security.
Audio at rest
Stored in private object storage. On S3-compatible storage, every object is written with server-side encryption (AES-256, or a KMS key you specify). Encryption at rest is provided by the storage provider.
Secrets at rest
Two-factor secrets and your external-cloud credentials are encrypted by the application with AES-256-GCM, each bound to its owner. Tokens and recovery codes are stored only as keyed hashes. Encryption keys are kept outside the database.
Integrity
SHA-256 for every upload chunk and every file, re-verified after processing, sampled daily in storage, and checked on every restore and desktop download.

08

Audit history

Hash-chained
Each entry includes the hash of the one before it, so a change to history breaks the chain and can be located. The database refuses edits and deletions of audit rows.
What’s recorded
Sign-ins and failures, two-factor changes, session revocations, role changes, invitations, uploads, approvals with the file checksum, downloads, share links opened and downloaded, storage connections, restores and device changes.
Who can read it
Organization admins, for their own organization.

09

Your own cloud and your computer

Narrow permissions
Google Drive: only files the app created. Dropbox and OneDrive: an app folder. It cannot read the rest of your storage.
Never destructive
Backups never overwrite or delete your files. If something changed on your side, both copies are kept and a conflict is raised.
Desktop
The desktop app stores its sign-in in the operating system keychain, verifies every download before replacing a file, and never deletes locally without moving to a trash folder first. Its local control interface only answers the same machine and refuses requests from web pages.

Who can do what

The same role model the server enforces. Pick a person.

Hayati EP · People PROTECTED

Karim can

  • Listen (allowed)
  • Comment at a timestamp (allowed)
  • Add versions and stems (allowed)
  • Download originals (allowed)
  • Edit lyrics, credits, metadata (allowed)
  • Send private, stream-only links (allowed)
  • Send downloadable links (allowed)
  • Approve a version (allowed)
  • Invite people (allowed)
  • Archive and restore (allowed)
  • Move to Trash; delete forever (confirm it’s you) (not allowed)
  • Storage and backup settings (not allowed)
  • Security policy (require 2FA) (not allowed)
  • Transfer ownership (not allowed)
  • Mark the Official Master (allowed)
  • Lock a master, or release a lock (confirm it’s you) (not allowed)
  • Download Official Masters (allowed)
  • Export social clips (allowed)
  • See campaign plans and calendars (allowed)
  • Plan campaigns, releases and shoots (allowed)
  • Add content ideas and upload edits (allowed)
  • Approve content before it posts (allowed)
  • Schedule and post content, record results (allowed)
  • Work with creators and send creator packs (allowed)
  • Track press and media (allowed)
  • Prepare and deliver to DSPs (allowed)
  • See the campaign budget and spend (allowed)

Checked on the server for every request. Without access, a song simply doesn’t exist for you: the answer is “not found”, not “forbidden”.

—

What we don’t claim

Not end-to-end encrypted. Our servers transcode audio for streaming and analyse it for waveforms and loudness, so they can read it. We don’t describe this as zero-knowledge.

No certifications yet. We don’t hold SOC 2 or ISO 27001 today, and won’t show a badge until we do.

Independent testing is planned, not done. We’ll say so here when a third-party penetration test has been completed.

No single sign-on yet. SAML or OIDC single sign-on and automated provisioning are not available today.

Questions

Is VYNLT end-to-end encrypted?

No. To stream, draw waveforms and measure loudness, our servers process audio, so we don’t claim end-to-end or zero-knowledge encryption. Audio is encrypted in transit and, on S3-compatible storage, at rest by the storage provider. Access is controlled by roles, short-lived signed links and the policies above.

Do you have SOC 2 or ISO 27001?

Not at this time. We won’t display a certification until we hold it. If your organization needs a security questionnaire answered, write to security@vynlt.com.

Can labels require two-factor for everyone?

Yes. Turn on “Require two-factor” in the organization’s security policy. You can also require admins to use passkeys or security keys.

How do I report a vulnerability?

Email security@vynlt.com with steps to reproduce. Please don’t access other people’s data or disrupt the service while testing.

Security your legal team can read.

Questions from a security review? Write to security@vynlt.com.