If you find a security flaw in Texas Inference, tell us. We do not punish good-faith research. The same contact is in our security.txt.
1. Report a flaw
Email [email protected]. Say what you found, how to reproduce it, and what it affects. Email works for a first report. Send enough to triage and keep exploit details short. We reply with a secure channel for details.
Please do not post the flaw publicly or tell anyone else until we have had a chance to fix it.
2. In scope
- This website and its pages
- The reservation, payment, and signing flows
- The public API of the lane and rental services
- The software that runs inside our confidential virtual machines, and the way it uses attestation
3. Out of scope
- Denial of service, load testing, and anything that degrades the service for others
- Social engineering of our staff, customers, or vendors, and phishing
- Physical attacks on our offices or on the data center
- Flaws in our subprocessors' systems. Report those to them. See the subprocessors page.
- Flaws in Intel, NVIDIA, or other hardware. Report those to the vendor, and tell us too if they touch our service.
- Reports that rely only on missing headers or settings with no demonstrated effect
4. Safe harbor
If you report a flaw to us as section 1 describes and act in good faith, we do not sue you and we do not report you to law enforcement. Good faith means you:
- stay within the scope above
- test only with accounts you own, or have permission to use
- do not read, copy, change, or destroy data that is not yours
- stop and tell us the moment you reach any data that is not yours
- do not hurt other customers or the service
- give us a fair time to fix the flaw before you disclose it
We cannot bind other companies or the authorities. This section does not permit anything the law forbids. If a third party takes action over work that follows this policy, we say publicly that you acted within it.
5. What to expect
| Step | Our target |
|---|---|
| We acknowledge your report | Within 3 business days |
| We confirm whether it is a flaw and how serious it is | Within 10 business days |
| We tell you the plan and update you at least every 14 days | Until it is fixed |
| We fix a critical flaw | As fast as we can. Within 30 days is our target |
| Coordinated public disclosure | Within 90 days of your report, or sooner by agreement |
These are targets and not guarantees. If we need longer, we tell you why.
6. Credit and rewards
We credit researchers by name on request, with their permission. We do not pay rewards.
7. Machine readable
/.well-known/security.txt follows RFC 9116.