Security & Vulnerability Disclosure

Inopia AB · Version 1.0 · Last updated 2026-07-11

Summary

Inopia AB (operating InRange AI) welcomes reports from security researchers and users about vulnerabilities in our systems. This policy describes how to report safely, what to expect from us, and our safe-harbor commitment to good-faith research.

Our posture

Scope

In scope:

Out of scope:

What we want to hear about

RCE, injection, XSS, authentication bypass, privilege escalation, broken access control (including IDOR), SSRF, exposure of user data (PII, chat content, glucose events) or credentials, and business-logic flaws with security impact. Lower priority: missing headers without an exploit path, raw scanner output, and best-practice suggestions without security impact.

How to report

Email security@getinrange.ai with a description, reproduction steps, impact assessment, the platform/version tested, and your contact info. A PGP key will be published here once generated — until then, ask for an encrypted channel in a first (non-sensitive) email. Machine-readable contact: /.well-known/security.txt (RFC 9116).

What to expect

Safe harbor

We will not pursue legal action against researchers who act in good faith: stay within the scope above, avoid privacy violations and service degradation, access only the minimum data needed to demonstrate impact, and give us reasonable time to fix issues before public disclosure. If in doubt, ask first — we answer.