Scoreflection
Security

Product security

Last updated: 18 August 2026

This page is two things: how to tell us about a security problem, and what we commit to in return. It is also the information the EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires us to make available, and the policy that /.well-known/security.txt points at.

1. Reporting a vulnerability

We want to hear about it. Report through the address on our contact page and put “security” in the subject line, so it is routed rather than queued.

What helps us most:

  • What you found, and which part it affects — the app, the API at api.scoreflection.com, the community forum, or this site.
  • Enough detail to reproduce it. A short sequence of requests beats a scanner report.
  • What you think the impact is, and whether you believe it is being exploited.
  • How you would like to be credited, if you would.

What we commit to:

  • We confirm receipt before we do anything else, so you know it arrived.
  • We tell you what we think it is and what we intend to do about it.
  • We fix what we can fix, and say so plainly when we cannot fix something quickly.
  • We will not pursue legal action against you for research done in good faith under this policy, and we will say publicly that a report came from outside if you want the credit.
  • We ask for 90 days before public disclosure, or less if a fix ships sooner. If we go quiet on you, publish — silence from us is not a reason for a problem to stay unreported.

Two things we ask you not to do. Please do not run automated scanners against the API: the score-recognition endpoint is compute-bound and rate-limited, and from where we sit a load test is indistinguishable from abuse. And please do not access, modify or delete other people's data — if you need to demonstrate something at volume or against real accounts, ask first and we will arrange a window.

Anything involving the safety of a child goes to the child safety contact instead. It is read on a different schedule.

2. How long we ship security updates

A security fix reaches you in a new version of the app, through the store you installed it from. We do not patch older builds: the fix is in the next version, which is why leaving automatic updates on is the shortest path between a fix existing and you having it.

While you have a paid plan, keeping the service in conformity with the contract — security updates included — is owed to you for the whole term of that contract. That is sec. 327f BGB rather than a promise we are adding on top, and it does not depend on anything on this page.

We have not declared a fixed support period under Art. 13 (8) of the Cyber Resilience Act. That declaration falls due when the Act's product requirements start to apply on 11 December 2027, and it will be published here when it does. We would rather state a period we can keep than a longer one we cannot.

3. How updates reach you

  • The app updates through the store you installed it from — Google Play or the App Store. Leaving automatic updates on is the shortest path between a fix existing and you having it.
  • The server, the API and the forum we run ourselves, so security fixes there take effect without you doing anything.
  • Security updates are free of charge, and are shipped separately from feature work whenever the fix can be separated.

4. What is in the product

We keep a bill of materials (SBOM) of the third-party components we ship, in CycloneDX format, regenerated whenever we audit dependencies. It covers the resolved dependency tree, not just the handful we name in a build file. It is available on request, and to market surveillance authorities as the Cyber Resilience Act requires.

We check that inventory against public vulnerability databases monthly and before every deployment.

5. When something goes wrong at our end

If a vulnerability in Scoreflection is being actively exploited, or a security incident affects the service, we notify the competent CSIRT and ENISA within the deadlines set by Art. 14 of the Cyber Resilience Act, and we tell affected users what happened and what to do about it. Where personal data is involved, the GDPR's own notification duties (Art. 33 and 34) apply on top and are shorter.

Fixed vulnerabilities are described publicly once a fix is available and users have had a fair chance to install it. We publish them on the security advisories page, which is empty until the first one is due.

6. What Scoreflection does not collect

Worth stating here because it bounds what a breach could ever expose: the app has no advertising SDKs and no third-party trackers, sheet music you scan is not stored on our servers, and every telemetry bucket is off until you switch it on. The detail is on the privacy page.

7. Changes

We update this page as the product and our commitments change. The date at the top is the last change.