We take security disclosures seriously. This page describes how to report a suspected vulnerability and what you can expect from us.
How to report
Email security@inferagen.ai with:
- A description of the issue and potential impact
- Reproducible steps (PoC or screenshots)
- Affected URL, environment, or component
- Your name and contact (so we can credit you)
Please do not exploit a vulnerability beyond what is necessary to prove it, and never access, copy, or modify customer data.
Our commitments
- Acknowledge your report within 24 hours.
- Provide an initial assessment within 5 business days.
- Resolve valid issues within 90 days (sooner for critical severity).
- Publicly acknowledge your contribution on this page (with your permission).
Out of scope
- Denial-of-service or social-engineering attacks
- Vulnerabilities in third-party services we don't operate
- Reports requiring physical access to a customer device or infrastructure
Bug bounty
We do not currently offer a paid bug bounty. We do publish a Hall of Thanks for valid reporters once issues are mitigated.
Safe harbour
Researchers acting in good faith under this policy will not be pursued for legal action. We will work with you, not against you.