Security

How we protect your files

  • Everything travels over HTTPS (obviously). Files and account data are encrypted at rest with AES-256.
  • Audio and artwork sit in private storage with no public URLs. Playback uses short-lived signed links.
  • Access to accounts and projects is checked on our servers against your permissions. Shared content is reached only through its link.
  • Share links use long random tokens. You can add a password, prevent downloads, or disable a link anytime.
  • Accounts support two-factor authentication. Sign-up, sign-in, and share passwords are protected against bots and guessing.
  • We monitor the platform with error tracking, security logs, and alerts.

We're security-cautious realists. No system is 100% secure.

WAVDROP was built with security in mind from day one. We keep testing and improving our protections, because keeping music sharing safe truly matters to us. Still, no online service can promise it will never be breached or go down, and we can't either. New kinds of attacks appear all the time, especially in the AI era, so we keep working on this, with ongoing testing and observability.

We can't guarantee that WAVDROP will always be available, error-free, or free from unauthorized access. To the extent the law allows, we aren't liable for harm caused by someone who gets past these safeguards despite the reasonable precautions we take. Our Terms say the same thing.

What you can do

  • Use a strong password, turn on two-factor authentication, and monitor your in-app notifications for activity on your projects.
  • Share links carefully. Anyone with a link can open it, so add a password to sensitive ones.
  • Keep your own backups. We are not a backup service, and we don't aim to be one.

Working on highly sensitive or unreleased material? Contact contact@wavdrop.link and we can walk you through how your files are protected.

Reporting a vulnerability

Found a security issue? Email contact@wavdrop.link with steps to reproduce. We aim to reply to security reports within 1–2 business days, and we'll keep you updated.

If you act in good faith and follow these rules, we won't take legal action against you:

  • Only test with your own accounts. Don't access or keep other users' data beyond what you need to show the issue.
  • No denial-of-service, spam, social engineering, or physical attacks.
  • Give us reasonable time to fix it before going public.

Our providers' own systems, such as Vercel, Supabase, and Cloudflare, are out of scope, and so are reports without real impact, such as missing headers. We don't run a paid bug bounty, but we're happy to thank you publicly.