Legal

Security & Responsible Disclosure

Effective 22 August 2026

01

Security programme

Incld uses defence-in-depth controls appropriate to an early-stage hosted developer platform. Current measures include HTTPS, secure session cookies, WorkOS-hosted authentication, email verification, scoped API keys, hashed stored API credentials, signed webhook delivery, role-based project access, isolated staging and production applications and databases, managed PostgreSQL backups, structured audit events, and production error monitoring when configured.

We review dependencies and infrastructure changes through version control and automated tests. Access to production systems is limited to authorised operators and providers. No security programme can guarantee that an incident will never occur.

02

Responsible disclosure

Send vulnerability reports to [email protected]. Include the affected URL or component, reproduction steps, likely impact, and a safe proof of concept. Do not include secrets or unrelated personal data in the initial message.

Act in good faith: avoid privacy violations, service degradation, social engineering, persistence, data destruction, accessing other users' data, or automated high-volume scanning. Stop testing and report immediately if you encounter sensitive data.

03

Our response

We aim to acknowledge credible reports within five business days, investigate promptly, keep the reporter reasonably informed, and remediate according to risk. We will not pursue legal action for good-faith research that follows this policy, but this is not permission to violate law or third-party systems.

For security questionnaires, incident notices, or enterprise requirements, contact [email protected].