Last updated: September 13, 2026
If you have found a vulnerability in Incleus we want to hear about it, and this page says how to tell us and what happens next. Be aware up front that there is no bounty programme: we are small and cannot pay for findings. What we can offer is a quick answer from a person, credit if you want it, and a commitment not to come after you for looking.
Email security@incleus.com with enough detail to reproduce the problem — a URL, the steps, and what you saw. If you would rather not send the details over email, say so in the first message and we will arrange another way.
The marketing site, the application, the API routes behind it, the public payment page a client opens from a link, and the documents we send by email.
Our providers' own infrastructure — Supabase, Vercel, Stripe, Anthropic and Resend — which should go to them directly, and which we will help you route if you are unsure. Also: anything needing physical access or a compromised device, social engineering, scanner output with no demonstrated impact, and missing hardening headers or rate limits with no exploit behind them.
Two-step verification is optional rather than mandatory today, and that is a published decision rather than an oversight — a report amounting to “MFA is not enforced” tells us something we have already written down. The same goes for the absence of an uptime commitment. Section 3 of the privacy policy is the current, honest account of what protects your data and where it stops.