Skip to main content

    Security & Responsible Disclosure

    Last updated: August 11, 2026

    1. Our Approach to Security

    Decision systems operate on mission-critical enterprise telemetry and industrial workflows. We treat security as a fundamental architectural constraint rather than a perimeter add-on.

    Our security architecture is guided by three core engineering principles:

    • Explainable by Default: Systems are engineered with transparent access controls, deterministic decision logic, and comprehensive audit telemetry.
    • Secure & Zero-Trust: Strict role-based access control (RBAC), TLS 1.3 encryption in transit, AES-256 encryption at rest, and micro-segmentation across environments.
    • Engineered for Resilience: Systems are designed to degrade safely under stress or partial network disruption without failing silently or exposing sensitive data.

    2. Reporting a Vulnerability

    We welcome contributions from security researchers and the broader technical community to help keep our infrastructure safe. If you believe you have identified a security vulnerability in any Infinite Castle system, domain, or service, please report it immediately to our security team.

    DEDICATED SECURITY INBOX

    security@infinitecastle.dev

    Please encrypt sensitive submission details where possible and include step-by-step reproduction steps, proof-of-concept scripts, and impacted endpoints.

    3. What to Expect (Response Commitments)

    When you report a vulnerability in good faith following this policy, we commit to the following response parameters:

    • Acknowledgment Timeline: We will acknowledge receipt of your vulnerability submission within 24 hours.
    • Validation & Assessment: Our engineering team will confirm the existence of the vulnerability and assess its severity within 72 hours.
    • Progress Updates: We will provide regular status updates at least once every 14 business days until remediation is complete.
    • Public Recognition: With your permission, we will publicly credit your contribution upon verified resolution.

    4. System Scope

    Please review the target boundaries below before conducting vulnerability research:

    ✔ IN SCOPE

    • *.infinitecastle.dev web applications and static domains.
    • Publicly accessible REST/GraphQL API endpoints.
    • Authentication and session management mechanisms.
    • Subdomain takeover risks owned by Infinite Castle.

    ✖ OUT OF SCOPE

    • Denial of Service (DoS / DDoS) or network volumetric flooding attacks.
    • Social engineering, phishing, or spear-phishing of employees or partners.
    • Physical security attacks on offices, servers, or personnel.
    • Vulnerabilities in third-party cloud infrastructure providers or external service providers.

    5. Safe Harbor Policy

    We consider vulnerability research conducted in compliance with this policy to be authorized. We pledge not to initiate civil or criminal legal action or file complaints with law enforcement against researchers who conduct security research in good faith, avoid privacy violations, destroy confidential data obtained during testing, and refrain from degrading system performance.

    6. Contact Us

    For security inquiries or vulnerability submissions, please email our security team directly at security@infinitecastle.dev.