Responsible Disclosure Policy
Last updated: August 23, 2026
How to report
Email security@infrarails.ai with a description of the issue, the steps to reproduce it, and its potential impact. Include proof-of-concept material if you have it — screenshots, request/response captures, or a minimal reproduction script. Encrypt sensitive details if you can; if not, send what you have and we'll follow up for detail.
Do not include real customer data in your report. If you encounter what appears to be real personal or confidential data while testing, stop, note where you found it, and report the exposure itself rather than exfiltrating or retaining the data.
Scope
In scope: the production Infrarails platform and website at infrarails.ai and its subdomains, and the TrustProxy gateway. Testing must comply with our Acceptable Use Policy — in particular, only test against your own account and data, or systems you are otherwise explicitly authorized to test; do not run automated scanning that could degrade service for other users; and do not attempt denial-of-service, social engineering, or physical-security attacks.
Out of scope: third-party services we integrate with but do not operate (cloud infrastructure providers, payment processors, and other sub-processors) — report those directly to the relevant provider. Findings that require physical access to a device, or that rely on already-compromised credentials, are also out of scope unless they demonstrate a real platform vulnerability beyond the credential compromise itself.
Safe harbor
We will not pursue legal action against you, or report you to law enforcement, for good-faith security research that:
- Stays within the scope described above,
- Avoids privacy violations, data destruction, and service disruption,
- Gives us a reasonable opportunity to investigate and remediate before any public disclosure, and
- Does not exploit a finding beyond what's needed to demonstrate it.
This safe harbor applies to research conducted consistent with this policy. It does not authorize actions that violate the law on someone else's behalf, or testing against systems or data you are not authorized to access.
What to expect
We aim to acknowledge reports and investigate promptly, but as a small early-stage team we do not currently commit to a fixed response-time SLA or offer paid bounties. We will keep you updated as we work through a confirmed issue and will credit researchers who ask to be credited once a fix ships, unless you ask us not to.
See also our Security page for our broader security posture, our Acceptable Use Policy for permitted testing activity, and our Data Processing Agreement for how we handle a confirmed data-related incident with enterprise customers.