Date: 2026-08-19
The Inqora team takes the security and integrity of our multi-agent intelligence ecosystem, cognitive memory stores, desktop overlays, and APIs seriously. We appreciate the responsible disclosure of security vulnerabilities by the community.
We actively provide security patches and updates for the following components on the main branch:
| Component | Target Ecosystem / Runtime | Supported |
|---|---|---|
| apps/web | Next.js 16 / React 19 | β |
| apps/server | Node.js Express / Vector DB / BullMQ | β |
| apps/blinky | Electron / React 19 Overlay | β |
| apps/agentos | Go Agent Execution Runtime | β |
| apps/rag-pipeline | Python FastAPI / RAG Services | β |
| apps/mobile-app | Expo / React Native | β |
| packages/* | Shared Libraries (@repo/ui, orchestrator) |
β |
| agent-factory/* | Sub-agent configurations & tools | β |
If you discover a potential security vulnerability within Inqora or any associated packages, please do NOT open a public GitHub issue.
- GitHub Security Advisory (Private): Submit a draft advisory via GitHub's Security Advisories feature on the repository.
- Direct Security Contact: If private advisories are unavailable, send details to
security@inqora.devor directly reach out to the project maintainers.
To help us triage and resolve the issue swiftly, please include:
- A description of the vulnerability and its potential impact.
- Affected component(s) (e.g.,
apps/server,apps/agentos,apps/blinky). - Step-by-step instructions or Proof-of-Concept (PoC) scripts to reproduce the issue.
- Details of any potential fix or mitigation you might have developed.
- Initial Triage: We will acknowledge receipt of your vulnerability report within 48 hours.
- Assessment & Status Updates: We will provide an assessment and timeline for a patch within 5 business days.
- Coordinated Disclosure: Once a fix is verified and deployed, we will coordinate public disclosure and provide appropriate credit to the reporter.
When building and deploying within the Inqora ecosystem, adhere to the following baseline security practices:
- Never commit
.envfiles or hardcode API keys (OpenAI, Anthropic, Gemini, DeepSeek, Slack tokens, Pinecone, Qdrant). - Use local
.envfiles created from.env.exampletemplates and keep them ignored in.gitignore.
- Sanitize and validate untrusted user inputs before passing them into agent context and RAG indexing pipelines.
- Apply strict system boundaries and tool execution whitelists when invoking external CLI commands or sandbox execution in
apps/agentos.
- Keep
nodeIntegration: falseandcontextIsolation: truein Electron BrowserWindow instances. - Limit IPC exposure to validated channels defined within preload scripts.
- Isolate workspace memory vectors per user session/tenant.
- Avoid storing plain-text PII (Personally Identifiable Information) in long-term vector embeddings and episodic memory logs.
Thank you for helping keep Inqora and the AI ecosystem secure!