Email security@getinner.ai with:
For sensitive reports, request our PGP key first via the same address.
Do not open a public issue, tweet the finding, or scan real customer packages to test. See "Safe harbor" below for what we authorize.
| Severity | Ack within | Fix target |
|---|---|---|
| Critical (RCE, sandbox escape, verdict-signature forgery) | 24h | 7d |
| High (auth bypass, admin escalation, DoS with easy vector) | 3 business days | 30d |
| Medium (info disclosure, weak validation) | 5 business days | 60d |
| Low | 10 business days | Next release |
In scope:
getinner.ai) and API (/api/*)@inner/* npm packages and the inner CLIOut of scope:
We will not pursue civil or criminal action against researchers who:
We are not currently running a paid bounty program. We publicly credit reporters (with permission) and are happy to provide LinkedIn / GitHub endorsements. Once we're funded past pre-seed, we'll formalize a paid program.
If a vulnerability affects the broader supply-chain ecosystem (npm, PyPI, or a specific package we scanned that turned out to be actually malicious), we will coordinate disclosure with the relevant registry, OSV, and GHSA. We'll credit you consistently across channels.