Security approach
Inbxer is designed for support data that may contain sensitive business context. Security work focuses on reducing access, making activity traceable and giving self-hosted teams control over their own infrastructure.
Identity and access
Workspace access is scoped by roles and permissions. Administrators control membership and sensitive configuration. Service access is limited to people and systems that need it to operate or support the product.
- Role-based workspace permissions
- Secure password and session handling
- API tokens that can be revoked
- Auditability for sensitive administrative actions
Data protection
Cloud traffic is encrypted in transit. Stored data, attachments and backups are protected using the controls provided by the hosting environment. Secrets are kept outside application source code.
Secure development
The public repository makes the application architecture reviewable. Changes are tested before release, dependencies are monitored and security fixes are prioritized according to impact.
Self-hosting responsibility
Self-hosted operators control their network, updates, backups, storage, model providers and access policies. The project documentation provides a starting point, but each operator remains responsible for hardening their deployment for its environment.
Report a vulnerability
Please do not disclose an unpatched vulnerability publicly. Send a clear description and reproduction steps to hello@inbxer.com with the subject “Security report”. Reports will be acknowledged and triaged as quickly as possible.