Security & Vulnerability Disclosure
Inopia AB · Version 1.0 · Last updated 2026-07-11
Summary
Inopia AB (operating InRange AI) welcomes reports from security researchers and users about vulnerabilities in our systems. This policy describes how to report safely, what to expect from us, and our safe-harbor commitment to good-faith research.
Our posture
- NIS 2-aligned security operations: incident response, disclosure policy, MFA, audit logging.
- EU-hosted infrastructure (Stockholm) with encryption at rest and TLS 1.3 in transit.
- CI security gates on every change: dependency CVE audit, secret scanning, SAST, SBOM per release.
- PII redaction in logs and error tracking; least-privilege access controls.
- GDPR data export and right-to-erasure built into the product.
Scope
In scope:
- The InRange AI iOS app (App Store / TestFlight)
- Backend API (
inrange-api.fly.dev,api.getinrange.aiand subdomains) - This website (
getinrange.ai) - Telegram and Signal bot integrations
Out of scope:
- Third-party subprocessors (Fly.io, Anthropic, OpenAI, Apple, Postmark) — report to them directly
- CGM providers (Dexcom, Libre, Eversense)
- Attacks against users' own devices or Apple/Google accounts
- Denial-of-service testing without explicit permission
- Social engineering against Inopia personnel; physical security
What we want to hear about
RCE, injection, XSS, authentication bypass, privilege escalation, broken access control (including IDOR), SSRF, exposure of user data (PII, chat content, glucose events) or credentials, and business-logic flaws with security impact. Lower priority: missing headers without an exploit path, raw scanner output, and best-practice suggestions without security impact.
How to report
Email security@getinrange.ai with a description, reproduction steps, impact assessment, the platform/version tested, and your contact info. A PGP key will be published here once generated — until then, ask for an encrypted channel in a first (non-sensitive) email. Machine-readable contact: /.well-known/security.txt (RFC 9116).
What to expect
- Acknowledgement within 3 business days
- Triage and severity assessment within 10 business days
- Coordinated public disclosure after 90 days, or earlier by mutual agreement
- Public credit (with your permission) — no paid bounty program yet, but validated findings get swag
Safe harbor
We will not pursue legal action against researchers who act in good faith: stay within the scope above, avoid privacy violations and service degradation, access only the minimum data needed to demonstrate impact, and give us reasonable time to fix issues before public disclosure. If in doubt, ask first — we answer.