Security
Security Disclosure
Found a vulnerability? Tell us directly — we'd rather hear from you first than find out the hard way.
Reporting a Vulnerability
If you've found a security issue in StreamTranslate — on our website, control panel, Twitch extension, or API — email us at [email protected] with a description of the issue and steps to reproduce it. We read every report personally.
Please don't publicly disclose an issue before we've had a reasonable chance to respond and fix it. We won't pursue legal action against good-faith security research conducted under this policy.
What to Expect
- Acknowledgement — we aim to confirm we've received your report within 2 business days.
- Updates — we'll keep you posted as we investigate and fix the issue.
- No action needed from you — please don't access, modify, or exfiltrate other users' data. A description and proof-of-concept is enough.
Machine-Readable Contact
Automated tools can find our disclosure contact at /.well-known/security.txt (RFC 9116).
Last updated: July 24, 2026