Acknowledge
We confirm receipt within 5 business days.
Trust · Vulnerability disclosure
Inscendo runs a unilateral safe-harbor program for good-faith security research, and we publicly credit researchers who responsibly disclose valid issues. The full legal terms, including scope and our acknowledgement and triage timelines, live in our Vulnerability Disclosure Policy.
Process
We confirm receipt within 5 business days.
We assess severity and reproducibility within 15 business days.
Coordinated public disclosure within 90 days, or sooner with your consent.
If you make a good-faith effort to comply with the Vulnerability Disclosure Policy (staying within scope, avoiding privacy violations, not destroying or modifying data, and giving us reasonable time to respond before public disclosure), Inscendo will consider your activity authorized for purposes of the Computer Fraud and Abuse Act and equivalent state laws, and won't pursue civil or criminal action against you, and will request that prosecutors do the same.
Acknowledgements
We list every researcher who reported a valid issue and asked to be credited, once the fix is live. Entries show a severity band and a general category rather than the affected component: a category says what the researcher found, a location would tell the next attacker where to look. Where the technical detail is worth publishing, it goes in an advisory and is linked here.
No one is listed yet.
No valid report has been credited so far. If you find something, this is where your name goes.