Inferaq Trust Centre

Responsible Disclosure Policy

How security researchers can report vulnerabilities to Inferaq safely, what is in scope and how reports will be handled.

Last updated: 19 September 2026

Thank you for helping protect Inferaq and its users.

If you believe you have found a security vulnerability in an Inferaq-controlled system, report it promptly and follow this policy. Inferaq will work in good faith with researchers who act lawfully, minimise harm and respect privacy.

1. How to report

Email info@inferaq.com with the subject “CONFIDENTIAL SECURITY REPORT”. Do not send passwords, private keys, personal data or exploit data in the first message. State that you need a secure exchange method if sensitive evidence is necessary.

Include the affected hostname, product or page; vulnerability type; reproducible steps; potential impact; any limited proof-of-concept; your contact details; and your disclosure plans. Reports should be in English where possible.

2. In scope

  • public services and domains demonstrably controlled by Inferaq;
  • authentication, authorisation or access-control failures;
  • cross-site scripting, injection and request-forgery vulnerabilities with credible impact;
  • exposure of Inferaq-controlled confidential or personal data;
  • serious AI security issues that cross a genuine permission or data boundary; and
  • other weaknesses likely to cause material harm to Inferaq, clients or users.

3. Out of scope

  • third-party services not controlled by Inferaq;
  • social engineering, phishing, physical intrusion or attacks on staff;
  • denial of service, stress testing, high-volume automated scanning or actions that degrade availability;
  • accessing, changing, deleting, retaining or sharing data beyond the minimum necessary to demonstrate the issue;
  • testing another person’s account or using stolen credentials;
  • mere absence of optional headers, version disclosure or low-impact best-practice observations without an exploit path;
  • prompt-injection demonstrations that do not cross a permission, confidentiality or integrity boundary; and
  • demands for payment, threats or public disclosure before a reasonable remediation period.

4. Researcher expectations

Act in good faith; comply with applicable law; use your own accounts and data; stop when you encounter personal or confidential information; avoid persistence and lateral movement; do not exfiltrate data; keep information confidential; and give Inferaq a reasonable opportunity to investigate and remediate.

5. Inferaq’s response

Inferaq aims to acknowledge a credible report within five business days and provide an initial triage update within ten business days. Remediation time depends on severity, complexity and third-party dependencies. Inferaq may request further evidence, coordinate a disclosure date and credit the researcher with permission.

6. Safe-harbour statement

Where a researcher makes a genuine good-faith effort to follow this policy, Inferaq does not intend to initiate legal action solely for the authorised research. This statement does not authorise violation of law, third-party rights, client contracts or systems outside Inferaq’s control, and it cannot bind law-enforcement bodies or third parties. If you are unsure whether testing is permitted, ask before proceeding.

7. Rewards and public disclosure

Inferaq does not currently operate a bug-bounty programme and cannot promise payment. Do not assume a reward. Coordinate publication with Inferaq; premature disclosure can increase risk to users and may fall outside this policy.

8. Privacy

Reporter details and report evidence are used to investigate, communicate, protect systems and meet legal obligations. They may be shared with affected suppliers, clients, advisers or authorities where necessary and will be protected as described in the Privacy Notice.

Last updated: 19 September 2026