AT Informatics

Security

How these tools are built, what they can reach, and how to report a problem · last updated 01 October 2026

Found something? Email aftertimetechnologies@gmail.com. You will get a human reply within 5 working days. We will not take legal action against anyone who reports a problem in good faith under the terms below.

1. The short version

AfterTime is desktop software. There is no AfterTime server, no account and no database of customers, because there is nothing for us to hold. The realistic risks are therefore local ones: what the software can read on your machine, what it can change in your projects, and what it sends if you deliberately connect it to a cloud AI provider.

2. Architecture, in security terms

ComponentRunsReaches
Application On your computer, under your user account Your REAPER project, its media files, and its own install folder
REAPER bridge Inside REAPER, as a script REAPER loads The REAPER project you have open, through REAPER’s own scripting API
Local interface A server bound to your own machine Not exposed to your network or the internet
Cloud AI provider Only if you configure one Receives text about your session. Never audio. See Privacy.

3. What the installer does, and does not do

4. Your credentials

If you configure a cloud AI provider you supply your own API key. It is stored in AfterTime’s settings on your machine, in your user account, and is sent only to that provider. We never receive it, because there is nowhere for it to be sent to. Anyone with access to your user account can read it — the same as any other application’s settings — so use full-disk encryption and do not share a login.

5. Actions that change your work

Security for a tool like this is mostly about not destroying something irreplaceable. The rules the software follows:

None of that replaces your own backups. Keep them.

6. Supply chain

AfterTime depends on open-source Python libraries, all pinned to minimum versions and listed with their licences on the third-party licences page. Dependencies are installed from the Python Package Index at install time. We do not vendor binaries we have not built, and we deliberately exclude GPL-licensed components that we would not be permitted to distribute.

7. This website

This site is static HTML and CSS served by GitHub Pages.

Being accurate about what that does and does not cover. This site is hosted on GitHub Pages, which serves static files and gives us no way to set HTTP response headers. We checked what it actually sends rather than assuming, and the honest position is:

What the meta policy does enforce is the part that matters most here: script-src 'none' on a site that has no JavaScript, and default-src 'self' on a site that makes no third-party requests.

Configuration for the full header set is kept in the repository (_headers, .htaccess, nginx.conf.snippet) so it is ready if this ever moves to a host that supports headers. On GitHub Pages those files are inert, and saying so is the point.

8. Reporting a vulnerability

Email aftertimetechnologies@gmail.com. Please include what you found, how to reproduce it, and what you think the impact is. A proof of concept helps.

StageTarget
Acknowledgement5 working days
Initial assessment10 working days
Fix or documented mitigation90 days, sooner where we can
Public creditIf you want it, on release

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised, will not pursue or support legal action against you, and will work with you to resolve the issue. In return, please:

We do not currently run a paid bug bounty. We would rather say so than imply one.

9. Out of scope

10. What we do not claim

AfterTime has not had an external security audit. It is beta software written by a very small team. The statements on this page describe how it is built and what we have checked; they are not a guarantee that it is free of defects. Where we have not verified something, we say so — the Windows build is the current example, and it is marked as untested on the install page for exactly that reason.