Skip to content
Inscendo

Vulnerability Disclosure Policy

How to report a security issue, what's in scope, the safe-harbor terms, and our acknowledgement / triage / disclosure timelines.

Version 1.2 (August 29, 2026 — § 3(e) and § 6. The trust page told researchers Inscendo would "request that prosecutors do the same", and the Policy — the binding instrument — said no such thing. New § 3(e) states it: where a third party brings a claim, or a criminal referral or prosecution arises, from activity we determined was authorized, we take reasonable steps to make the authorization known and ask the prosecuting authority to do likewise. § 6 was a single sentence promising a hall of fame; it now states that consent comes first and silence means no listing, exactly what an entry shows (chosen name, date RESOLVED, severity band, general category), and what it deliberately withholds (endpoint, component, reproduction) with the reason — a category says what you did, a location tells the next attacker where to look. Technical detail goes to a § 7.8 advisory after the fix, linked from the entry. Adds an Inscendo obligation and narrows what we publish about a researcher; no researcher obligation is enlarged. Version 1.1 (August 29, 2026 — § 10 restated. It reproduced the contents of our `security.txt` and carried unresolved drafting placeholders in its Expires and Hiring lines, both of which were published. The stated expiry was also wrong: the file is served with a shorter expiry than twelve months, and `Hiring` is not published at all. § 10 now describes what the file contains rather than restating its field values, and names the file as authoritative where the two disagree, so the Policy cannot drift from it again. No change to scope, safe harbor, authorized conduct, reporting address, disclosure timelines, or any commitment made to a researcher.))Effective May 30, 2026legal/vulnerability-disclosure.md