Security policy

Last updated: 2026-07-01 · Machine-readable: /.well-known/security.txt

Inner is a supply-chain security product. If you found a vulnerability in Inner itself, thank you. This page explains how to report it and what to expect.

Reporting

Email security@getinner.ai with:

For sensitive reports, request our PGP key first via the same address.

Do not open a public issue, tweet the finding, or scan real customer packages to test. See "Safe harbor" below for what we authorize.

Response commitments

SeverityAck withinFix target
Critical (RCE, sandbox escape, verdict-signature forgery)24h7d
High (auth bypass, admin escalation, DoS with easy vector)3 business days30d
Medium (info disclosure, weak validation)5 business days60d
Low10 business daysNext release

Scope

In scope:

Out of scope:

Safe harbor

We will not pursue civil or criminal action against researchers who:

  1. Report vulnerabilities in scope in good faith.
  2. Do not access, modify, or destroy data belonging to other users.
  3. Do not disrupt the Service beyond what's minimally necessary to demonstrate the issue.
  4. Give us reasonable time to remediate before public disclosure — 90 days by default; less if we agree, more if we ask.

Bug bounty

We are not currently running a paid bounty program. We publicly credit reporters (with permission) and are happy to provide LinkedIn / GitHub endorsements. Once we're funded past pre-seed, we'll formalize a paid program.

Coordinated disclosure

If a vulnerability affects the broader supply-chain ecosystem (npm, PyPI, or a specific package we scanned that turned out to be actually malicious), we will coordinate disclosure with the relevant registry, OSV, and GHSA. We'll credit you consistently across channels.