01
Current security posture
- Authentication is handled by Clerk.
- The backend enforces entitlement and trial limits.
- Backend owner checks restrict access to user projects, runs, logs, and files.
- Admin APIs require the local admin role.
- The current MockRunner does not execute user commands.
- Runtime, command, upload, output, and log limits are controlled by backend policy.
- Real sandbox execution is still being hardened.
- Docker, Firecracker, KVM, and other microVM support are planned or experimental and are not public by default.
02
What Innet does not claim
- Innet does not guarantee that submitted code is safe.
- Innet is not a replacement for code review or security review.
- Innet must not be used to run malware or conduct unauthorized testing.
- Innet is not a place to store secrets or sensitive production data.
- No service can promise complete security or uninterrupted availability.
03
Responsible disclosure
If you believe you found a security issue, contact [email protected] with enough detail to reproduce it safely. Do not exploit the issue, access another user’s data, retain data you encounter, or disrupt the service.
We do not currently operate a paid bug bounty program unless explicitly stated. Sending a report does not create an entitlement to payment.