Inferent

Security Policy

Version: 1.0Last Updated: July 2026Jurisdiction: Global

1. Introduction

Security is a core value at Inferent. We are committed to protecting the data and privacy of our users, and we continuously invest in security practices, tooling, and culture. This policy describes how we approach security and how you can report vulnerabilities responsibly.

2. Scope

This policy applies to all systems owned and operated by Inferent Group S.A. de C.V. and its subsidiaries, including all domains under inferent.xyz and associated product platforms.

3. Our Security Practices

  • Encryption: Data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 or equivalent standards.
  • Access Controls: We apply the principle of least privilege across our internal systems and conduct regular access reviews.
  • Authentication: We support multi-factor authentication (MFA) and enforce strong password policies.
  • Monitoring: Our infrastructure is continuously monitored for anomalies, intrusion attempts, and policy violations.
  • Dependency Management: We regularly audit and update third-party dependencies to address known vulnerabilities.
  • Incident Response: We maintain a documented incident response plan and conduct periodic drills.

4. Vulnerability Disclosure

If you discover a security vulnerability in any Inferent system, we encourage you to disclose it to us responsibly. We ask that you:

  • Report the vulnerability to us before publicly disclosing it
  • Give us a reasonable amount of time (typically 90 days) to investigate and address the issue
  • Not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Not access, modify, or delete data belonging to other users
  • Not conduct denial-of-service attacks or social engineering

In return, we commit to:

  • Acknowledge receipt of your report within 5 business days
  • Provide regular updates on the status of our investigation
  • Not pursue legal action against researchers acting in good faith
  • Publicly credit researchers (with their permission) upon resolution

5. Responsible Disclosure Program

We accept vulnerability reports via our security email. High-severity vulnerabilities may be eligible for recognition or a monetary reward at our discretion, based on impact and quality of the report.

In Scope: Authentication, authorization, data exposure, injection vulnerabilities, remote code execution, and cross-site scripting on any Inferent-operated system.

Out of Scope: Social engineering, physical attacks, spam, denial of service, issues in third-party software not under our control.

6. Contact

Report security vulnerabilities to:

Email: [email protected]
PGP: Available upon request
For general security questions: [email protected]