Trust Center
Vulnerability disclosure
If you believe you have found a vulnerability in Inlinea software or in the managed service, we want to hear from you, and we will not pursue good-faith research.
How to report
Four steps
- 1Write to the security teamUse the security contact published in our security.txt and on this page, encrypted with our PGP key if the report is sensitive.
- 2Tell us what you foundThe component, the steps to reproduce, the impact you believe it has, and how to reach you.
- 3We acknowledgeWithin two business days, with a reference and a first assessment of severity.
- 4We fix and creditWe keep you informed, fix the issue in a release, publish an advisory when it affects customers, and credit you if you wish.
Safe harbour
What we ask, and what we promise
- Good faithTest only against your own tenant or systems you are authorised to test; do not access, modify or exfiltrate other customers' data; stop and report once you have demonstrated the issue.
- No legal actionWe will not pursue or support legal action against research conducted in line with this policy, and we will say so to third parties if asked.
- Response targetsAcknowledgement within two business days; a fix target by severity, communicated with the acknowledgement.
- CreditResearchers who wish to be named are credited in the advisory.