Operational Policy
Effective: 2026-09-21Last Updated: 2026-09-21

Security Policy

Authoritative policy outlining security principles, practices, account protections, infrastructure safeguards, and vulnerability disclosure.

1. Purpose

Security is fundamental to the trust and integrity of the StrmFarm platform.

This Security Policy describes the principles, practices, and safeguards implemented to protect user accounts, artist identities, playback verification, campaign integrity, platform infrastructure, and platform data.

As StrmFarm continues to evolve, our security program will also evolve to address emerging threats, technological advancements, regulatory requirements, and industry best practices.

This Policy should be read together with our Privacy Policy, Terms of Service, Verification Framework, Fraud & Platform Integrity Policy, Community Guidelines, Artist Campaign Policy, and other applicable platform policies.

2. Security Principles

Every security decision at StrmFarm is guided by the following principles:

  • Security by Design: Security is incorporated into platform architecture from the beginning rather than added after deployment.
  • Least Privilege: Access to systems, infrastructure, and sensitive information is limited to only what is necessary to perform authorized responsibilities.
  • Defense in Depth: Multiple independent layers of technical and operational controls work together to reduce security risks.
  • Continuous Improvement: Security controls are regularly reviewed and improved as new threats, technologies, and operational requirements emerge.
  • Privacy by Default: Where practical, systems are designed to minimize unnecessary data collection while protecting users and platform integrity.

3. Account Security

Users are responsible for maintaining the security of their StrmFarm accounts.

Users should:

  • Use strong, unique passwords.
  • Keep login credentials confidential.
  • Protect access to their email accounts.
  • Notify StrmFarm immediately if unauthorized activity is suspected.
  • Keep account recovery information current.

Users may not share, transfer, sell, rent, or otherwise provide access to their accounts to other individuals.

StrmFarm may temporarily restrict account access when suspicious activity is detected to protect users and platform integrity.

4. Authentication & Authorization

StrmFarm uses secure authentication and authorization mechanisms to verify user identity and control access to platform resources.

Current authentication measures include:

  • Secure password authentication.
  • JSON Web Token (JWT) authentication.
  • Refresh token session management.
  • Email verification.
  • Password reset verification.
  • Session validation.
  • Device-based account protection.
  • Role-based access controls for administrative functions.

Certain actions may require additional verification before they can be completed.

5. Multi-Factor Authentication & Identity Verification

StrmFarm supports additional identity verification for security-sensitive account actions.

Where applicable, users may receive verification emails containing secure codes or verification links before completing actions such as password resets, email verification, or sensitive updates.

Artist verification requires additional identity review before artist profiles may receive verified status.

6. Data Encryption

StrmFarm implements encryption and secure communication practices designed to protect user information and platform data:

  • HTTPS encryption for data transmitted between users and the platform.
  • Secure password hashing using industry-standard algorithms.
  • Encryption of sensitive authentication credentials.
  • Secure session handling.
  • Encrypted communications with supported third-party services where applicable.

7. Infrastructure Security

StrmFarm employs multiple layers of infrastructure security designed to protect platform availability, integrity, and reliability:

  • Secure cloud infrastructure.
  • Network isolation where appropriate.
  • Environment-based configuration management.
  • Secure deployment pipelines.
  • Firewall protections & rate limiting.
  • Infrastructure monitoring.

Production secrets and sensitive configuration values are managed through secure environment variable systems and are not stored within application source code.

8. Third-Party Services & Integrations

StrmFarm integrates with trusted third-party providers (Digital Streaming Providers, cloud hosting, database services, transactional email, analytics, payment providers, and blockchain infrastructure).

Each provider maintains its own security practices and policies.

9. Playback Verification & Fraud Protection

Protecting authentic listening activity is a core security objective.

StrmFarm continuously evaluates playback activity using proprietary verification systems designed to identify fraudulent behavior while protecting legitimate listeners and artists.

To preserve platform security, StrmFarm does not publicly disclose verification thresholds, fraud detection methodologies, risk models, or other confidential anti-abuse mechanisms.

10. Security Monitoring & Incident Response

StrmFarm continuously monitors platform operations to identify security events, suspicious activity, infrastructure issues, and potential abuse.

When security incidents occur, StrmFarm investigates affected systems, restricts access where necessary, preserves evidence, notifies affected users where required by law, and implements remediation measures.

11. Vulnerability Disclosure

Security researchers and community members are encouraged to report potential vulnerabilities responsibly.

Individuals should not exploit vulnerabilities, access unauthorized data, or publicly disclose issues before StrmFarm has had a reasonable opportunity to address them.

Security reports may be submitted to:

  • Security Email: security@strmfarm.com

12. User Responsibilities

Users play an important role in maintaining platform security by protecting credentials, maintaining accurate information, keeping devices secure, and avoiding attempts to bypass verification or security controls.

13. Security Updates

StrmFarm may update security controls, authentication methods, infrastructure, or operational procedures without prior notice where necessary to protect users and platform integrity.

14. Contact Information

Questions regarding this Security Policy or vulnerability reports may be directed to:

  • Security Team: security@strmfarm.com
  • General Support: support@strmfarm.com