Security

Built with a verifiable release path

SoundOverlay’s public security information distinguishes production controls from work that still requires release confirmation.

Release verification

Version, filename, size, architecture, download host, signing states, and SHA-256 metadata are validated before a public link can render.

No game injection

SoundOverlay does not inject code into games or hook game rendering APIs. Its overlays use normal Windows desktop-window functionality.

Supported versions

No public application version is currently listed as supported. This page will identify supported release lines after the first production installer is published.

Installer and update signing

Windows Authenticode status and Tauri updater-signature status are separate release facts. Neither is marked active on the download page until it is confirmed in validated metadata.

Checksum verification

Production releases are expected to publish a SHA-256 checksum alongside the immutable installer path. Verification instructions will be added with the first release.

Responsible reporting

Please avoid publicly disclosing an unpatched vulnerability. Include the affected version, environment, reproduction steps, expected and observed behavior, and any evidence that helps confirm impact. Do not include unrelated personal data.

Response process

Reports will be acknowledged and triaged as capacity allows. A formal response-time commitment and safe-harbor policy require owner and legal confirmation before publication.