Security Vulnerability Disclosure Policy

We welcome responsible vulnerability reports to help keep our customers and systems safe.

Report a vulnerability

Primary contact: security@innomos.com

Optional encryption: Use our OpenPGP key (link it from Encryption: in /.well-known/security.txt).

What to include:

Our response process

Targets above are best-effort and may vary by complexity and third-party dependencies.

Safe harbor (good-faith testing)

We will not pursue legal action against researchers who:

Out of scope

Rules of engagement

Recognition

If you would like public recognition, tell us in your report. If we maintain an acknowledgments page, it will be linked from Acknowledgments: in security.txt.

PGP key and security.txt

Machine-readable contact details are published at https://<your-domain>/.well-known/security.txt in accordance with RFC 9116.