Latent

Vulnerability disclosure · last updated September 2026

Found a security issue? Tell us.

Reports go straight to the person who built Latent. We acknowledge every report within two business days.

Scope

In scope
  • The vLLM plugin
  • The review service and its console
  • The gateway
  • The sidecar
  • The runlatent.ai website
Out of scope
  • Social engineering of anyone at Latent or at a customer
  • Denial of service
  • Third-party services, such as Netlify, Cal.com and Hugging Face
  • vLLM itself. Report those issues to the vLLM project.

How to report

Email founders@runlatent.ai. Include the component and its version, the steps to reproduce the issue, and what an attacker could do with it. Proof-of-concept code helps.

What we commit to

  • Acknowledgement of your report within two business days.
  • Updates while we investigate and fix it.
  • Credit by name, if you want it.

Safe harbor

We will not pursue legal action over research done in good faith under this policy. Good faith means three things.

  • Test only what you run. Latent runs inside customers' environments. Use your own install, and never test a deployment you do not own.
  • Take only what you need. Access no more data than it takes to show the issue, and keep none of it.
  • Do no harm. Avoid anything that degrades a service or damages data.