Security
Found something? Email aftertimetechnologies@gmail.com. You will get a human reply within 5 working days. We will not take legal action against anyone who reports a problem in good faith under the terms below.
1. The short version
AfterTime is desktop software. There is no AfterTime server, no account and no database of customers, because there is nothing for us to hold. The realistic risks are therefore local ones: what the software can read on your machine, what it can change in your projects, and what it sends if you deliberately connect it to a cloud AI provider.
2. Architecture, in security terms
| Component | Runs | Reaches |
|---|---|---|
| Application | On your computer, under your user account | Your REAPER project, its media files, and its own install folder |
| REAPER bridge | Inside REAPER, as a script REAPER loads | The REAPER project you have open, through REAPER’s own scripting API |
| Local interface | A server bound to your own machine | Not exposed to your network or the internet |
| Cloud AI provider | Only if you configure one | Receives text about your session. Never audio. See Privacy. |
3. What the installer does, and does not do
- No Administrator or root. Everything is installed under your own user account. An installer that asks for elevation is an installer that can do anything, and this one does not need to.
- An isolated runtime. Dependencies are installed into a virtual environment belonging to AfterTime, not into your system Python.
- It copies one script into REAPER and adds a clearly marked block to REAPER’s startup file. The block is spliced in between named markers, so anything else in that file is preserved, and the uninstaller removes exactly that block and nothing else.
- It refuses to ship the wrong files. The packaging step has a size budget and an exclusion list, and it aborts rather than continue if the payload is unexpectedly large. That check exists because it caught a real mistake: a hidden virtual environment that would have bundled 441 MB of unrelated compiled libraries into a 10 MB package.
- It verifies afterwards. The install is re-read from disk and fails loudly if the bridge is missing, the startup block did not land, the dependencies do not import, or the application itself does not start. That last check was added after an install passed every other test and the product could not boot.
4. Your credentials
If you configure a cloud AI provider you supply your own API key. It is stored in AfterTime’s settings on your machine, in your user account, and is sent only to that provider. We never receive it, because there is nowhere for it to be sent to. Anyone with access to your user account can read it — the same as any other application’s settings — so use full-disk encryption and do not share a login.
5. Actions that change your work
Security for a tool like this is mostly about not destroying something irreplaceable. The rules the software follows:
- Every change is a single REAPER undo step.
- Anything that writes asks first, and shows what it will do.
- The software checks it is operating on the project you meant, and refuses if the session has changed since it last measured.
- It never deletes audio.
- After writing, it reads the result back out of REAPER instead of trusting its own return value.
None of that replaces your own backups. Keep them.
6. Supply chain
AfterTime depends on open-source Python libraries, all pinned to minimum versions and listed with their licences on the third-party licences page. Dependencies are installed from the Python Package Index at install time. We do not vendor binaries we have not built, and we deliberately exclude GPL-licensed components that we would not be permitted to distribute.
7. This website
This site is static HTML and CSS served by GitHub Pages.
- No third-party requests. No fonts, scripts, analytics, trackers or embeds from any other host. Everything is served from this domain — open your browser’s network panel and check.
- No cookies, no local storage, no JavaScript.
- A Content-Security-Policy of
default-src 'self'withscript-src 'none', delivered in a<meta>tag.
Being accurate about what that does and does not cover. This site is hosted on GitHub Pages, which serves static files and gives us no way to set HTTP response headers. We checked what it actually sends rather than assuming, and the honest position is:
- HTTPS is enforced and plain HTTP is redirected to it with a 301, on a valid certificate. That part is real and you can verify it.
- There is no HSTS header. We previously said GitHub sets
one once HTTPS is enforced. We measured the live response and it does not.
The practical effect: the very first visit a browser makes over
http://is redirected rather than prevented. - There is no
X-Content-Type-Options: nosniff, and noX-Frame-OptionsorPermissions-Policy, because those are header-only and cannot be set on this host. frame-ancestorsis deliberately absent from the policy. The HTML specification ignores that directive when a policy is delivered by<meta>, so including it would look like clickjacking protection while doing nothing.
What the meta policy does enforce is the part that matters most here:
script-src 'none' on a site that has no JavaScript, and
default-src 'self' on a site that makes no third-party requests.
Configuration for the full header set is kept in the repository
(_headers, .htaccess, nginx.conf.snippet)
so it is ready if this ever moves to a host that supports headers. On GitHub
Pages those files are inert, and saying so is the point.
8. Reporting a vulnerability
Email aftertimetechnologies@gmail.com. Please include what you found, how to reproduce it, and what you think the impact is. A proof of concept helps.
| Stage | Target |
|---|---|
| Acknowledgement | 5 working days |
| Initial assessment | 10 working days |
| Fix or documented mitigation | 90 days, sooner where we can |
| Public credit | If you want it, on release |
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue or support legal action against you, and will work with you to resolve the issue. In return, please:
- Test only against your own installation.
- Do not access, modify or destroy anyone else’s data.
- Do not run denial-of-service tests, spam, or social-engineering attacks against us or our users.
- Give us a reasonable chance to fix the issue before disclosing it publicly.
We do not currently run a paid bug bounty. We would rather say so than imply one.
9. Out of scope
- Vulnerabilities in REAPER itself — report those to Cockos.
- Vulnerabilities in third-party plugins or AI providers — report those to their authors.
- Attacks that require an attacker to already have access to your user account. If someone is running code as you, the game is already over.
- Missing security headers on this static site that have no exploit path.
10. What we do not claim
AfterTime has not had an external security audit. It is beta software written by a very small team. The statements on this page describe how it is built and what we have checked; they are not a guarantee that it is free of defects. Where we have not verified something, we say so — the Windows build is the current example, and it is marked as untested on the install page for exactly that reason.