Protecting the music community
urTrax is designed to handle artist releases, listener accounts, purchases, and payouts with care. Security is an ongoing practice, not a claim that incidents are impossible.
Our approach
We use safeguards appropriate to the Service’s size, data, and risk. Depending on the system and implementation, these may include:
- encrypted HTTPS connections for information transmitted between supported clients and urTrax;
- managed authentication and access controls;
- least-privilege access for personnel and service accounts;
- separation of production environments and administrative functions;
- logging and monitoring of security-relevant activity;
- dependency, vulnerability, and configuration review;
- backups and recovery procedures for appropriate systems;
- restricted access to production data;
- incident assessment, containment, remediation, and notification procedures; and
- periodic review of vendors that handle important information.
Payment security
Payments and payouts are processed by Stripe. urTrax does not intend to store complete payment-card numbers. Stripe may collect payment, bank, tax, identity, and fraud-prevention information to process transactions and meet legal obligations.
Account safety
Users should:
- use a unique password and never share authentication codes;
- keep email and payout accounts secure;
- verify the domain before entering credentials;
- review artist payout details after account changes;
- avoid sending passwords, full card numbers, or identity documents by ordinary email; and
- report suspicious activity promptly.
urTrax will never ask for your password by email.
Reporting a vulnerability
If you believe you found a security vulnerability, email rob@urtraxapp.com with the subject Security Report and include:
- the affected page, endpoint, or feature;
- steps to reproduce the issue;
- the potential impact;
- relevant screenshots or logs with personal information removed; and
- a safe way to contact you.
Do not access other users’ information, disrupt the Service, use social engineering, perform denial-of-service testing, deploy malware, or publicly disclose an unresolved issue. We will acknowledge good-faith reports when practicable. This reporting channel does not create a promise of payment, employment, confidentiality, or immunity from law.
Security incidents
If an incident affects personal information, we will investigate and provide notices to affected people and authorities when required by applicable law. Because email itself may be insecure, do not email sensitive credentials or complete financial information.