Sinfonie

Security

Effective 5 September 2026.

Reporting a vulnerability

If you believe you have found a security issue in Sinfonie, the website, or the sign-in relay, email [email protected] with “Security” in the subject. Include what you found, how to reproduce it, and the app version. We acknowledge reports within 3 business days, keep you informed while we fix the issue, and credit you if you wish. We ask that you give us reasonable time to fix before disclosing publicly, and that you do not access data that is not yours. Good-faith research within these terms will not lead to legal action. There is no paid bounty programme at this time.

How the app protects data

Scope

In scope: the Sinfonie desktop app, sinfonie.dev and its functions. Out of scope: the third-party services Sinfonie connects to (Slack, Jira, Linear, GitHub, AI providers), which have their own programmes.