Reporting a security problem

If you have found a vulnerability in Incleus we want to hear about it, and this page says how to tell us and what happens next. Be aware up front that there is no bounty programme: we are small and cannot pay for findings. What we can offer is a quick answer from a person, credit if you want it, and a commitment not to come after you for looking.

How to report

Email security@incleus.com with enough detail to reproduce the problem — a URL, the steps, and what you saw. If you would rather not send the details over email, say so in the first message and we will arrange another way.

What we promise

  • We will acknowledge your report within five business days.
  • Within ten business days we will tell you whether we have reproduced it, what we think the severity is, and what we intend to do.
  • We will tell you when it is fixed, and we will not quietly close a report.
  • We will credit you by name on this page if you want that, and keep you anonymous if you prefer.
  • We will not bring or support legal action against you for security research carried out in good faith and within what this page asks. If a third party brings a claim about research that followed this page, we will make that clear to them.

What we ask of you

  • Give us reasonable time to fix the problem before you describe it publicly. Ninety days is the usual figure and we will not ask for longer without telling you why.
  • Do not access, change, keep or share anybody else's data. Tenant isolation is the thing we would most like tested — so ask us and we will set you up an organization with our own data in it, and you will never need to touch a customer's.
  • Do not degrade the service for anyone: no denial of service, no load testing, no bulk automated scanning against production.
  • No social engineering, phishing or physical attempts against our staff, our customers or our providers. Those reach people who did not agree to be tested.

In scope

The marketing site, the application, the API routes behind it, the public payment page a client opens from a link, and the documents we send by email.

Out of scope

Our providers' own infrastructure — Supabase, Vercel, Stripe, Anthropic and Resend — which should go to them directly, and which we will help you route if you are unsure. Also: anything needing physical access or a compromised device, social engineering, scanner output with no demonstrated impact, and missing hardening headers or rate limits with no exploit behind them.

Things we already know

Two-step verification is optional rather than mandatory today, and that is a published decision rather than an oversight — a report amounting to “MFA is not enforced” tells us something we have already written down. The same goes for the absence of an uptime commitment. Section 3 of the privacy policy is the current, honest account of what protects your data and where it stops.