Skip to main content

Security boundaries

  • The host signs in through browser device authorization.
  • Guests join with temporary, role-specific credentials rather than the host’s account.
  • Hosted relay access is authorized by short-lived server-issued tokens.
  • Relays forward media for the authorized stream identity without transcoding it.
  • A hosted Scene Share Stage code admits a guest to the backstage roster but does not contain sender or receiver media credentials.
  • The OBS plugin is not trusted with hosted service secrets or billing enforcement.

Media handling

Hosted relays forward live product media and do not normalize, gate, downmix, or transcode it. The products have two narrowly scoped temporary-data exceptions:
  • Music Collab can hold a prepared backing asset in a bounded in-memory relay cache so both performers receive the same track. It is not a recording of either participant’s microphone.
  • A Scene Share guest can explicitly publish one silent 320x180 JPEG preview still. The control plane normalizes and size-limits it, encrypts it at rest, and expires it after at most 10 minutes or when the Stage ends. Preview sharing is off until the guest enables it; capability metadata alone does not upload Program pixels.
When selected, Scene Share keeps the guest’s H.264 video and AAC audio muxed as one live stream. Waiting guests do not send the full Program feed. Consult the Privacy Policy for the service’s complete legal data-handling terms.

Secrets users may encounter

Never publish:
  • Guest keys.
  • Stage codes.
  • Receiver SRT URLs.
  • Account or device tokens.
  • OBS stream keys.
  • API keys or private keys.
  • Payment information.
OBS logs and screenshots can include URLs, status text, source names, or environment details. Review and redact them before sharing.

Device authorization

The dock opens a browser authorization and may show a short device code. Complete authorization only on the intended vAudioLink domain. If the browser cannot open, use the dock’s copied URL rather than manually searching for a sign-in page. After approval, the installation saves a revocable device credential so Host or Send can reuse that authorization after OBS restarts. An active installation renews its authorization while it remains valid; an expired, incomplete, or server-rejected credential is cleared and requires a new browser approval. A temporary account-status network failure should not silently erase a valid saved sign-in. Open Profile → Signed-in OBS plugins in the account panel to review and revoke installations. Revoke a device you no longer control; its next authenticated request will fail and the dock will require authorization again.

Licensing

vAudioLink-authored application code, binaries, assets, and documentation are proprietary and all rights are reserved. They are not licensed for redistribution or commercial reuse without prior written permission. Third-party components and vendored interfaces remain subject to their own license terms and notices.

Safe support bundle

Include:
  • Product and plugin version.
  • OBS version.
  • Host, guest, sender, or receiver role.
  • Exact error text.
  • Approximate time and time zone.
  • A reviewed OBS log.
Remove:
  • Complete credentials and URLs.
  • Account tokens.
  • Private IP or hostname details that are unnecessary.
  • Personal information unrelated to the incident.

Report a suspected exposure

  1. End and recreate the affected room or Stage. In Music Collab, Rotate guest key can replace an exposed guest key instead.
  2. Revoke the device if account authorization may be affected.
  3. Preserve a redacted timeline and relevant logs.
  4. Contact vAudioLink support.