Report a vulnerability
Primary contact: security@innomos.com
Optional encryption: Use our OpenPGP key (link it from Encryption: in /.well-known/security.txt).
What to include:
- Clear description of the issue and affected product/service/URL
- Steps to reproduce (proof-of-concept where safe)
- Impact assessment (what an attacker could achieve)
- Logs, screenshots, request/response samples (redact sensitive data)
Our response process
- Acknowledgement: we aim to acknowledge receipt within 3 business days.
- Triage: we assess severity, scope, and ownership, and may request clarifications.
- Fix & verify: we work on remediation and validation.
- Disclosure: coordinated disclosure timeline agreed with the reporter when possible.
Targets above are best-effort and may vary by complexity and third-party dependencies.
Safe harbor (good-faith testing)
We will not pursue legal action against researchers who:
- Act in good faith to avoid privacy violations, data destruction, and service disruption
- Only access data necessary to demonstrate the issue, and do not retain or disclose it
- Do not use social engineering, physical attacks, or denial-of-service techniques
- Provide us a reasonable opportunity to remediate before public disclosure
Out of scope
- Denial of service (DoS/DDoS), spam, or physical/social engineering
- Issues in third-party services we do not control (please report to the vendor)
- Non-security issues (e.g., feature requests, UI bugs)
- Reports without a security impact (e.g., missing security headers with no exploit path)
Rules of engagement
- Do not exploit beyond what is needed to prove the vulnerability
- Do not modify or delete data
- Do not access other users’ accounts or data
- Stop testing immediately if you risk impacting availability
Recognition
If you would like public recognition, tell us in your report. If we maintain an acknowledgments page, it will be linked from Acknowledgments: in security.txt.
PGP key and security.txt
Machine-readable contact details are published at https://<your-domain>/.well-known/security.txt in accordance with RFC 9116.