SAVINGSFinancial gain :Save €1,500 to €3,000 / year per studio (Zero software royalties)
NO SUBSCRIPTIONSoftware cost :€0 / month · Open-source, zero recurring fees, no vendor lock-in
OPEN SOURCEFull transparency :Public source code on GitHub: auditable by anyone, zero black box
MAC & MAC MINIStudio appliance :Perfect control unit: near-total silence, dual HDMI screens & auto-launch
APPLE SILICONM4 to M6 chips :Apple Silicon tuning: instant 4K playback with zero heat build-up
VERIFIED MINI PCSAccessible hardware :Verified refurbished mini PC (HP EliteDesk, industrial fanless) from €161
VERIFIED GUIDEAmazon purchases :Every hardware guide product is hand-verified: real ASIN, checked price, authentic photo
ALREADY OWN A LAPTOPZero repurchase :No purchase needed: close your existing laptop in clamshell mode and plug in a simple hub
GRAPHICS ACCELERATIONSmooth playback :Hardware-accelerated engine: buttery smooth 4K & 2K 60 fps playback
100% OFFLINEOutage proof :Operates without Internet: resilient against fiber cuts and ISP outages
TOUCH KIOSKSelf-service :Member touchscreen with live class countdown and easy selection
DUAL SCREENSMulti-display :Simultaneous feeds: main workout screen + gym floor TVs
24/7 GYM RADIOBackground music :Continuous music flow with seamless crossfade and automated voice alerts
CUSTOM CONTENTCatalog freedom :100% Agnostic: play your own workouts (Cycling, HIIT, Yoga, Pilates)
MULTI-OSCross-platform :Windows 10/11, macOS, Linux, Android tablets and iPadOS exploration
NATIVE ANDROIDDedicated app :Available on touchscreen tablets to control your fitness studio seamlessly
LINUX APT REPONative updates :GPG-signed .deb package on apt.bobine.fit: native Linux updates via apt update
SIMPLE REMOTEEasy control :Choice of 2.4 GHz wireless clicker or local smartphone QR web app
PRIVACY & GDPRData sovereignty :100% Local: zero analytics, zero cameras, your data stays in your club
BLACKOUT RECOVERYElectrical resilience :Autonomous auto-recovery and instant playout resume after power outage
1-CLICK BACKUPUniversal export :Export and restore your entire schedule and video catalog in a single ZIP
ECO-FRIENDLYLow power draw :From 6 Watts in fanless configuration: silent, cost-effective and eco-friendly
Security

Report a vulnerability

Bobine is an open-source project maintained independently. If you believe you found a flaw in the website, the Tor mirror, the APT repository or the software, here is how to report it and what to expect.

Last updated: 8 October 2026

1. How to report

Write to [email protected], or open a private vulnerability report on GitHub: https://github.com/FantasmaGlad/Bobine/security/advisories/new. The private GitHub report is preferable for anything exploitable: only the maintainers can see it.

We ask that any report containing exploitable details be encrypted. Our OpenPGP public key for receiving reports (Ed25519 and Curve25519, expires October 2028) has the fingerprint 23CA D324 C507 FB0F 97E6 AECA 6E4C 020E F8BD FEB2. Download it at https://bobine.fit/.well-known/security.asc or let your client discover it: gpg --locate-keys [email protected]. Check the fingerprint before sending.

The /.well-known/security.txt file is signed with this key: curl -s https://bobine.fit/.well-known/security.txt | gpg --verify. The fingerprint is also published independently in the official software repository (github.com/FantasmaGlad/Bobine/SECURITY.md and docs/security folder), on the dedicated security.bobine.fit site (hosted separately) and in the DNS (openpgp4fpr TXT and OPENPGPKEY records): check that it matches on at least two channels before sending a report.

Create your own key pair and attach your public key to your message (or tell us where to fetch it): we will reply encrypted to it. Example: gpg --quick-generate-key "Your Name <[email protected]>" future-default default 2y then gpg --armor --export [email protected]. Never share your private key.

If you cannot use PGP, use the private GitHub report rather than plain email. The /.well-known/security.txt file describes these channels in a machine-readable form (RFC 9116).

Please include: the affected address or component, steps to reproduce, the impact you observe and, if possible, a minimal proof of concept.

2. Scope

In scope:

  • the bobine.fit website and its server routes (Baamix assistant, catalog);
  • the Tor mirror of the site and of the APT repository;
  • the apt.bobine.fit package repository and its signing chain;
  • the Bobine software (github.com/FantasmaGlad/Bobine) and its installers (install.sh, install-tor.sh, Windows, macOS, Linux and Android packages).

3. Out of scope

Please do not report:

  • flaws in third-party services (Vercel, Cloudflare, GitHub, Amazon, AliExpress, Hugging Face, OpenRouter, Resend): contact their vendors directly;
  • social engineering, phishing, physical access;
  • denial-of-service attacks, load tests and mass automated scans;
  • findings without demonstrable impact (a missing non-exploitable header, displayed version, deliberately public files such as llms.txt or robots.txt);
  • content or translation errors (use the usual contact address).

4. What we do

We aim to acknowledge a report within 7 days and keep you informed of progress. As the project has a single maintainer, these timings are a goal, not a contractual commitment.

We ask for a reasonable time to fix before any disclosure: 90 days by default, extendable by mutual agreement or shortened if the flaw is already being exploited. Fixes are published in the release notes and we credit reporters who wish it.

5. Good-faith research

Research carried out in good faith within the scope above will not lead to any action from us. In return: do not access other people's data beyond what is strictly needed to demonstrate the flaw, do not modify or destroy data, do not disrupt the service, do not install persistence, and do not disclose anything before it is fixed.

There is no financial reward program (bug bounty).

6. Verifying the authenticity of downloads

The APT repository is signed. Primary key fingerprint: B77D 96D7 2F84 F36A CAA3 F872 9CBF 497D 829E E15A. The install-tor.sh script pins this fingerprint and stops if it differs. This signing key is separate from the key used to receive reports (section 1). Automatic updates verify the SHA-256 digest of the files published on GitHub Releases.

7. Acknowledgments

No report has been published so far. People who report a fixed flaw will be listed here, with their consent.

8. Key and document history

7 October 2026: policy published with a first report key (fingerprint 8208 FFD3 F7AB 4DD3 6B0A CDD8 4726 A378 F683 265A).

7 October 2026: this first key is revoked and removed the same day, a few hours after publication, because its passphrase could not be used. No report had been received and the private key was never exposed. The revoked public key, carrying its revocation signature, is published in the official software repository.

7 October 2026: current key created and published (23CA D324 C507 FB0F 97E6 AECA 6E4C 020E F8BD FEB2); security.txt signed with this key.

8 October 2026: dedicated disclosure site security.bobine.fit published and fingerprint added to the DNS of bobine.fit; a daily check verifies that every channel serves the same fingerprint.

Any change of key, fingerprint or commitment is recorded here.