Account protection
- Passwords are hashed and never stored in plain text.
- Sessions are managed by our authentication provider.
- We recommend strong, unique passwords.
This Security Policy describes how MSW protects accounts, content and user data.
Database row-level security ensures that profiles, listings, events, jobs and stolen-instrument reports can be edited only by their owner.
Administrators may review, approve, hide or remove content that violates the Terms or applicable law. Moderation actions are logged.
Only content that has been approved and published is visible to the public. Pending, rejected, archived, suspicious and spam content is excluded from public views.
Uploads are restricted to common image formats (JPEG, PNG, WebP) with size limits, and are stored under per-user paths.
Server-side secrets are stored as environment variables and never exposed to the browser. The service role key is used only on the server.
Visitor analytics are anonymous: we collect page paths, language and country but do not store IP addresses or personal identifiers.
If we become aware of a personal data breach, we will investigate, contain the incident, and notify affected users and the supervisory authority when required by law.
If you discover a security vulnerability, please report it privately to news@musicservices.world. Please do not publicly disclose the issue before we have had a reasonable time to respond.