inbound

Security

Last Updated: December 10, 2025

Vulnerability Disclosure

At Inbound, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.

If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

Out of Scope Vulnerabilities

The following vulnerability types are out of scope and will not be considered for review. Reports submitted for these issues will not receive a response.

  • Clickjacking on pages without sensitive actions
  • Cross-Site Request Forgery (CSRF) on forms without sensitive actions
  • Attacks requiring MITM or physical access to a user's device
  • Any activity that could lead to the disruption of our service (DoS/DDoS)
  • Content spoofing and text injection issues without showing an attack vector or ability to modify HTML/CSS
  • SPF/DKIM/DMARC email spoofing issues
  • Missing DNSSEC, CAA, CSP, X-Frame-Options, or other security headers
  • Lack of Secure or HTTP-only flag on non-sensitive cookies
  • Dead links or broken pages
  • Anything related to DNS configuration or email authentication records
  • Rate limiting issues or lack thereof
  • Self-XSS (Cross-Site Scripting that only affects the user themselves)
  • Reflected XSS without demonstrable impact
  • Missing best practices without demonstrable security impact
  • Theoretical vulnerabilities without working proof of concept
  • Vulnerabilities in third-party services or dependencies we don't control
  • Issues discovered through automated scanning tools without manual verification
  • Open redirects without demonstrable security impact
  • Username/email enumeration
  • Information disclosure with minimal security impact (e.g., stack traces, server version headers)
  • SSL/TLS configuration issues unless directly exploitable
  • Missing cookie attributes on non-session cookies
  • Logout CSRF
  • Reports from automated tools or scanners without manual validation

Note: Inbound reserves the right to designate any reported vulnerability as out of scope at our sole discretion.

What We Ask of You

Please Do:

  • Provide sufficient information to reproduce the problem, including steps, URLs, and screenshots
  • Give us reasonable time to respond and address the issue before any public disclosure
  • Make a good faith effort to avoid privacy violations, destruction of data, and disruption of service
  • Only interact with accounts you own or have explicit permission to test

Please Do Not:

  • Run automated scanners on our infrastructure or dashboard without prior authorization
  • Take advantage of the vulnerability beyond what is necessary to demonstrate the issue
  • Download, modify, or delete data that does not belong to you
  • Reveal the problem to others until it has been resolved
  • Use attacks on physical security, social engineering, distributed denial of service, spam, or applications of third parties
  • Demand payment or threaten disclosure before we have had time to investigate

How to Report a Vulnerability

You can report security vulnerabilities by emailing us at:

security@inbound.new

Please include the following information in your report:

  • Description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • Affected URLs, endpoints, or components
  • Any proof-of-concept code or screenshots
  • Your contact information for follow-up questions

Our Commitment

If you follow the guidelines above:

  • We will not take legal action against you regarding the report
  • We will handle your report with strict confidentiality and not share your personal details with third parties without your permission
  • We will keep you informed of the progress towards resolving the issue
  • We strive to resolve all issues as quickly as possible

Security Practices

We implement reasonable security measures to protect your data:

  • Data encryption in transit (TLS) and at rest
  • Secure cloud infrastructure hosted on AWS
  • Access controls and authentication
  • Regular security monitoring

Contact

For security-related inquiries, please contact us at:

EXON ENTERPRISE LLC

Security: security@inbound.new

Website: inbound.new