This page gathers the cybersecurity information about Sostenutoo: how to report a vulnerability to us, how long the product receives security updates, and how to use it securely. It addresses, among others, Regulation (EU) 2024/2847 (Cyber Resilience Act).
Last updated: 17 September 2026
2. Report a vulnerability
If you believe you have found a security flaw in Sostenutoo, email us at securite@sostenutoo.com. This is our single point of contact for security. If you prefer another channel, you can also write to us by post at the address above or through support@sostenutoo.com: we will forward it.
To help us, please include if possible:
- the affected part (website, iOS app, Android app) and its version;
- a description of the issue and its possible impact;
- steps to reproduce it;
- a way to reach you, and whether you wish to be credited.
You can write in French, English or Spanish. The security.txt file lists these details in a machine-readable format.
3. Coordinated vulnerability disclosure policy
What we do
- We acknowledge receipt of your report, normally within 10 business days.
- We analyse the issue and keep you informed of the key steps.
- We fix confirmed vulnerabilities within a timeframe proportionate to their severity, the most serious first.
- If the vulnerability lies in a third-party component used by Sostenutoo, we also report it to the person or organisation maintaining that component.
- Once a fix is available, we publish a security advisory (see section 4) and, if you wish, credit you by name.
What we ask of you
- Do not make the vulnerability public before the fix is available to users or, failing that, before 90 days from your report. This period can be extended by mutual agreement if the fix requires it.
- Test only with your own accounts, and do not access, modify or delete other users' data beyond what is strictly necessary to demonstrate the issue.
- Do not disrupt the service (no denial of service, no mass automated testing), do not send spam and do not use social engineering.
- Delete any data you may have obtained once the report is made.
We consider research that follows these rules to be conducted in good faith, and we do not intend to take legal action against it. We do not offer a bug bounty.
You may also report a vulnerability to CERT-FR (ANSSI), the coordinator in France.
4. Security advisories
When a vulnerability is fixed, we publish an advisory here describing the issue, the affected versions, its impact, its severity and, where relevant, what you need to do. We may wait until users have had time to install the update before publishing these details.
No advisories published to date.
5. Keeping you informed
If an actively exploited vulnerability or a severe incident affects the security of Sostenutoo, we inform the affected users, and all users where necessary, as soon as possible. Where relevant, we also tell them what measures they can take. Depending on the situation, this information is sent by email, by an in-app notification or through this page.
These obligations are in addition to those under the GDPR in the event of a personal data breach, described in the Privacy Policy.
6. Product identification
Sostenutoo comes in three forms, which share the same account and the same server:
A mobile app's version number is shown on its app store page and in your phone's settings. The web app is always served in its latest version.
7. Intended purpose and security properties
Sostenutoo is used to manage a music ensemble: members, events, attendance, programmes, sheet music, messaging and documents. It is intended for associations, schools and ensembles, their managers and their musicians.
Main protections:
- encrypted communications (HTTPS/TLS) between the apps and the server;
- authentication by password (stored hashed) or with Apple and Google;
- isolation of each ensemble's data at database level, and different permissions by role (member, administrator);
- payments processed by Stripe, Apple or Google: Sostenutoo does not store any card number;
- regular database backups.
8. Known or foreseeable risks
The following situations may expose your data or your ensemble's data:
- a weak password or one reused on other sites, or a phishing email impersonating Sostenutoo;
- a session left open on a shared or lost device;
- an administrator role granted too widely, or a former member still in the ensemble;
- an invitation link or code shared publicly while membership requests are open;
- a browser, operating system or app that is no longer updated, or a jailbroken or rooted phone;
- a third-party artificial intelligence assistant connected to your account, which acts with your permissions;
- files uploaded by other members (PDFs, images, documents): open them with the same care as any file you receive.
9. Support period and updates
Sostenutoo receives security updates at least until December 2032. This date can only be extended. Should we ever discontinue the service, we would notify you in advance.
- Security updates are free for all users, whether subscribed or not.
- Only the latest version of the apps is supported: updating is free, you just need to install it.
- The web app updates itself: simply reload the page.
- The mobile apps are updated through the App Store and Google Play, automatically if this option is enabled on your phone (the default setting). The app may also tell you that a new version is available.
10. Secure use instructions
Day to day
- Choose a unique, strong password, or sign in with Apple or Google.
- Sign out on shared devices. We will never ask for your password by email.
- Keep your browser, operating system and the app up to date.
- If you manage an ensemble: give the administrator role only to trusted people, remove members who leave and close membership requests when you are not recruiting.
- Disconnect artificial intelligence assistants you no longer use.
When a setting changes the security of your data
Granting an administrator role, opening membership requests, sharing an invitation link, adding a guardian or connecting a third-party assistant widens access to data. Review these settings regularly. Modified or unofficial versions of the apps are not supported.
Installing updates
- Web: reload the page, the latest version loads automatically.
- iPhone and iPad: App Store, tap your profile picture, then update Sostenutoo.
- Android: Google Play, tap your profile picture, "Manage apps & device", then update Sostenutoo.
Turning off automatic updates
We recommend keeping them on. If you prefer to turn them off or postpone them:
- iPhone and iPad: Settings, App Store, turn off "App Updates".
- Android: Google Play, profile picture, Settings, Network preferences, "Auto-update apps". You can also turn it off for Sostenutoo only from its store page (three-dot menu).
- Web: the web app is served from our servers, so it is always up to date and this setting does not exist.
Stopping use of Sostenutoo and deleting your data
- Delete your account from "My account" (web) or the profile settings (apps). Your data is then erased as described in the Privacy Policy.
- Uninstalling the app erases the data stored on the phone, but does not delete your account.
- On a shared computer, sign out before closing the browser.
Integration into other products
Sostenutoo is not designed to be integrated as a component into another product.
11. Declaration of conformity and software bill of materials
The EU declaration of conformity for Sostenutoo will be published on this page no later than the date of application of the corresponding requirements of Regulation (EU) 2024/2847, 11 December 2027.
We keep an up-to-date list of the software components used by Sostenutoo (software bill of materials, or SBOM). It is not published, but it is provided to the authorities on request.
← Back to Home