Security Advisories
This is the public security-advisory channel for Inqura, operated by JE Vectors LLC. Advisories and patched-release notices are published here, dated, and carried in an RSS feed you can subscribe to.
Licensed customers are also notified directly: nominate a security contact of record at onboarding and advisories are sent to that address. This page is the second path, and it is open to anyone — no account, no login, and no request to us is needed to read it.
Published advisories
No advisories to date.
No security advisory has been issued for any Inqura release since this channel was established. This statement is published deliberately, as a record rather than as an absence: an advisory channel with nothing on it should say that it is empty, rather than leave you guessing whether it is empty or broken. When an advisory is issued it appears on the page, newest first, and in this feed at the same moment.
Channel established August 26, 2026. This statement is also published to the RSS feed as INQ-STATUS-0001, so a subscriber can tell an active channel with nothing to report from one that has stopped working.
Subscribe
Advisories are published to an RSS 2.0 feed. Point any feed reader at:
https://inqura.ai/security/advisories.xml
There is no email subscription list. RSS is the only subscription mechanism we offer today, and it requires nothing from you but a reader. Licensed customers who need direct notification should use the security contact of record described above.
Reporting a vulnerability
Send vulnerability reports to security@inqura.ai. Reports from customers, assessors, and good-faith security researchers are all handled through that address. Please include enough detail to reproduce the issue, and the Inqura version you observed it on.
Coordinated disclosure
If you believe you have found a security vulnerability in Inqura, email security@inqura.ai. You do not need to have proof of exploitability, and you do not need to be a customer.
What we commit to. We acknowledge every report within 3 business days, and we tell you within 10 business days whether we have reproduced the issue and what we intend to do about it. If a report leads to a fix, we publish an advisory on this page identifying the affected versions, the severity, and the fixed version. We will credit you by name or handle if you want the credit, and we will not name you if you do not.
Safe harbor. If you follow the rules below, we will treat your research as authorized conduct. We will not bring a legal claim against you for it, we will not refer you to law enforcement for it, and if a third party brings a claim against you arising from research that followed these rules, we will make it known that your conduct was authorized.
The rules.
- Test only against
inqura.ai,app.inqura.aiandapp.nquiry.ai. Deployments of Inqura that run inside a customer's own AWS account are the customer's systems, not ours — we cannot authorize testing against them, and this safe harbor does not cover it. - Use your own account and your own test data. Do not access, modify, or store another person's data. If you encounter data belonging to someone else, stop, do not save a copy, and tell us what you saw in general terms.
- Do not degrade the service. No denial-of-service testing, no load or stress testing, no automated scanning heavy enough to affect other users.
- No social engineering, phishing, or physical access attempts against us, our staff, or our suppliers.
- Do not publish the details while we are fixing it. Give us 90 days from your report, or until we publish an advisory, whichever comes first. If we are not moving fast enough, tell us — we would rather agree a date with you than have you guess one.
- Stay within the law. Nothing here authorizes conduct that is unlawful independently of our permission, and nothing here binds anyone but us.
What is out of scope. Reports that describe a missing hardening measure without a demonstrated impact — absent security headers, permissive TLS ciphers, missing rate limits, self-XSS, clickjacking on pages with no state-changing action, output from an automated scanner with no working proof of concept, or issues in third-party services we consume. Vulnerabilities in AWS itself go to AWS, not to us.
There is no bounty. We are a small company and we do not pay for reports. We say so here rather than letting you find out after you have spent a weekend on it.
This is not a contract. These terms describe how we intend to behave, they can change, and the version that applies to you is the one published on this page on the day you report. Nothing here limits any right a customer has under their own agreement with us.
Approved by Joe Etherage, JE Vectors LLC — 2026-08-31. Last reviewed 2026-08-31.
Looking for our agreements and policies? See all legal documents or our trust and security overview. General questions: legal@inqura.ai.