Skip to content
Inscendo

Trust · Vulnerability disclosure

Found something? Tell us.

Inscendo runs a unilateral safe-harbor program for good-faith security research, and we publicly credit researchers who responsibly disclose valid issues. The full legal terms, including scope and our acknowledgement and triage timelines, live in our Vulnerability Disclosure Policy.

Process

Acknowledge in 5. Triage in 15. Coordinated disclosure within 90.

1

Acknowledge

We confirm receipt within 5 business days.

2

Triage

We assess severity and reproducibility within 15 business days.

3

Disclose

Coordinated public disclosure within 90 days, or sooner with your consent.

In scope
  • inscendoiq.com and any subdomain operated by Inscendo Automation Inc.
  • The Inscendo public APIs, including the agent service endpoints.
  • The capsule, widget and automation runtime, as exposed to a tenant you own.
  • Authentication and authorization flows, in your own tenant.
  • The Inscendo Browser Companion (v0.4.0+), in your own browser, attached to a tab on a domain you own.
  • Pre-deployment environments, only when our security.txt names them as in scope.
Out of scope
  • Other tenants' data, accounts, capsules or content: never test against a tenant you do not own.
  • Our third-party providers (hosting, AI, payments, messaging, DNS): report those to the vendor directly.
  • Denial-of-service, volumetric attacks, credential stuffing and password spraying.
  • Social engineering of Inscendo personnel, customers or vendors.
  • Physical attacks, and supply-chain attacks via packages we depend on.
  • Any site we do not operate, including similarly named ones.
Safe harbor

Good-faith research is welcomed, not prosecuted.

If you make a good-faith effort to comply with the Vulnerability Disclosure Policy (staying within scope, avoiding privacy violations, not destroying or modifying data, and giving us reasonable time to respond before public disclosure), Inscendo will consider your activity authorized for purposes of the Computer Fraud and Abuse Act and equivalent state laws, and won't pursue civil or criminal action against you, and will request that prosecutors do the same.

Acknowledgements

The researchers who made Inscendo safer.

We list every researcher who reported a valid issue and asked to be credited, once the fix is live. Entries show a severity band and a general category rather than the affected component: a category says what the researcher found, a location would tell the next attacker where to look. Where the technical detail is worth publishing, it goes in an advisory and is linked here.

No one is listed yet.

No valid report has been credited so far. If you find something, this is where your name goes.