Skip to content

Security: torrin-app/torrin

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in Torrin, please report it responsibly.

Do not open a public issue.

Email security@torrin.app with:

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment

We'll respond within 48 hours and work with you on a fix before any public disclosure.

Scope

  • internal/ -- open-source core
  • ghcr.io/torrin-app/torrin -- Docker image
  • torrin.app -- hosted service
  • stream.torrin.app -- streaming CDN
  • api.torrin.app -- REST API

Out of scope

  • Third-party services we depend on
  • Social engineering
  • Denial of service

There aren't any published security advisories