OpenStudio constructing the production surface
OpenStudio

Security

Security Policy

How OpenStudio handles release integrity, platform trust, and responsible vulnerability disclosure.

  • Last updated

    April 16, 2026

  • Disclosure contact

    support@openstudio.org.in

  • Response target

    Best-effort, typically within 7 days

  • Bug bounty

    None currently

Supported versions

Only the latest public release of OpenStudio is actively maintained. Older builds are not backport-patched as a general rule.

Before reporting a security issue in the desktop app or the website distribution flow, please upgrade to the latest public release and confirm the issue still reproduces there.

Verifying your download

Always download OpenStudio from openstudio.org.in or the official GitHub releases page. The website is the public distribution surface for the desktop app, and unofficial mirrors should not be treated as trusted release channels.

On macOS, you may need to approve the app manually in System Settings > Privacy & Security if Gatekeeper prompts you. Do not install builds from unofficial sources.

  • Download from openstudio.org.in or the official GitHub releases page
  • Check the release page for any integrity notes on the specific build
  • On macOS: allow the app in System Settings > Privacy & Security if Gatekeeper prompts you

Reporting a vulnerability

Email support@openstudio.org.in with the subject line "Security: OpenStudio" if you believe you found a vulnerability in the OpenStudio desktop app, website, release artifacts, or update metadata.

Please include a clear description of the issue, reproduction steps, affected version, affected platform such as Windows, macOS, or Linux, and how you discovered it. Please allow up to 7 days for an initial response before public disclosure.

Scope

In scope: the OpenStudio desktop application, the openstudio.org.in website, official release artifacts, and update metadata published for the app.

Out of scope: third-party DAW plugins, your operating system or local system configuration, and AI model or runtime files obtained from third-party providers outside the standard OpenStudio distribution flow.

Disclosure policy

OpenStudio follows coordinated disclosure. Please report issues privately first, allow reasonable time for investigation and a fix, and then disclose publicly when appropriate.

Credit will be given to reporters unless they request anonymity.

What we do not currently claim

OpenStudio does not currently claim SOC 2 compliance, formal security certifications, or a managed penetration-testing program for the current release cycle.

There is also no automated bug bounty program at this time.