Intrinsic Code
    AboutBuildTrackerTest suiteVerify a ReceiptSecurity
    → Trust · Intrinsic Code

    Security Disclosure

    Effective: June 24, 2026  ·  Last updated: June 24, 2026

    Intrinsic Code takes the security of our software seriously. We welcome reports from security researchers and value the work of the research community in helping us keep our product and our users safe. This policy explains how to report a vulnerability to us and what you can expect in return.

    01 / How to reportReporting a vulnerability

    Email your report to security@intrinsiccode.com. Please include enough detail for us to reproduce and validate the issue: a description of the vulnerability, the steps to reproduce it, the affected component or version, and any proof-of-concept material. If you are able to, please suggest a severity and potential impact.

    02 / Our commitmentWhat to expect from us

    • We will acknowledge receipt of your report within three business days.
    • We will work to validate and triage the issue, and we will keep you informed of our progress.
    • We aim to remediate confirmed vulnerabilities as quickly as is practical based on severity.
    • We will credit you for your discovery if you wish to be recognized, and we will respect your preference to remain anonymous.

    03 / Coordinated disclosureCoordinated disclosure

    We ask that you give us up to 90 days from the date of your report to investigate and address the issue before disclosing it publicly. We are committed to resolving issues promptly, and we are happy to coordinate the timing of any public disclosure with you. If a vulnerability is being actively exploited, please tell us in your report so we can prioritize it.

    04 / Safe harborSafe harbor

    We will not pursue or support legal action against researchers who report vulnerabilities to us in good faith and in accordance with this policy. We consider security research conducted under this policy to be authorized, lawful, and helpful. If you make a good-faith effort to comply with this policy during your research, we will work with you to understand and resolve the issue, and we will not recommend or pursue legal action against you.

    To qualify for safe harbor, you must:

    • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services.
    • Only access, store, or disclose the minimum amount of data necessary to demonstrate the vulnerability.
    • Not exploit the vulnerability beyond what is necessary to confirm it, and not use it to access or modify data belonging to others.
    • Give us a reasonable opportunity to resolve the issue before disclosing it publicly.

    05 / ScopeScope

    This policy applies to the Intrinsic Code product and the services we operate. Testing must not target the data, accounts, or systems of other users, and must not include physical attacks, social engineering, or denial-of-service testing.

    06 / PermissionA note on permission

    The presence of a security.txt file or this policy does not by itself grant permission to test any specific system. The authorization described here is limited to good-faith research consistent with the scope and conditions above.

    ← Back to home
    © 2026 Intrinsic Code Inc. · Patent Pending · All rights reserved.