Vulnerability Disclosure Policy
Last updated: June 2026
We take the security of our customers’ stores and their customers’ data seriously. If you believe you have found a security vulnerability in Inbox, we want to hear from you and we will work with you to confirm and fix it. This page explains how to report responsibly and what you can expect from us.
1. How to report
Email security_inbox@theagenticgroup.dev. Please do not open a public GitHub issue, post publicly, or disclose the issue to anyone else before we have had a chance to fix it.
2. What to include
To help us reproduce and triage quickly, include: a clear description of the issue, the steps to reproduce it (a proof-of-concept where possible), the affected URL or component, and your assessment of the potential impact.
3. Safe harbor
We will not pursue or support legal action against researchers who act in good faith and follow this policy. Good-faith research means you: avoid privacy violations and degradation of the service; only interact with accounts you own or have explicit permission to test; do not access, modify, or delete other people’s data; and give us a reasonable opportunity to fix the issue before disclosing it. If in doubt, ask us first.
4. Out of scope
The following are generally not eligible: denial-of-service (DoS/DDoS) testing; social engineering or phishing of our staff or customers; physical attacks; spam or content-injection without a security impact; automated-scanner output without a demonstrated, exploitable issue; and vulnerabilities in third-party services we rely on (please report those to the relevant provider — see our sub-processors).
5. Our commitment to you
- We aim to acknowledge your report within 3 business days.
- We aim to provide a triage assessment within 7 business days.
- We will keep you updated on remediation and coordinate timing of any public disclosure.
- With your permission, we are happy to credit you once the issue is resolved.
6. Machine-readable contact
Our security contact is also published at /.well-known/security.txt per RFC 9116.
See also our Security practices and Privacy Policy.