Policies

Security at Innet

A practical overview of the current beta security boundary, its limitations, and how to report a concern responsibly.

Last updated: June 2026
01

Current security posture

  • Authentication is handled by Clerk.
  • The backend enforces entitlement and trial limits.
  • Backend owner checks restrict access to user projects, runs, logs, and files.
  • Admin APIs require the local admin role.
  • The current MockRunner does not execute user commands.
  • Runtime, command, upload, output, and log limits are controlled by backend policy.
  • Real sandbox execution is still being hardened.
  • Docker, Firecracker, KVM, and other microVM support are planned or experimental and are not public by default.
02

What Innet does not claim

  • Innet does not guarantee that submitted code is safe.
  • Innet is not a replacement for code review or security review.
  • Innet must not be used to run malware or conduct unauthorized testing.
  • Innet is not a place to store secrets or sensitive production data.
  • No service can promise complete security or uninterrupted availability.
03

Responsible disclosure

If you believe you found a security issue, contact [email protected] with enough detail to reproduce it safely. Do not exploit the issue, access another user’s data, retain data you encounter, or disrupt the service.

We do not currently operate a paid bug bounty program unless explicitly stated. Sending a report does not create an entitlement to payment.