Vulnerability disclosure · last updated September 2026
Found a security issue? Tell us.
Reports go straight to the person who built Latent. We acknowledge every report within two business days.
Scope
In scope
- The vLLM plugin
- The review service and its console
- The gateway
- The sidecar
- The runlatent.ai website
Out of scope
- Social engineering of anyone at Latent or at a customer
- Denial of service
- Third-party services, such as Netlify, Cal.com and Hugging Face
- vLLM itself. Report those issues to the vLLM project.
How to report
Email founders@runlatent.ai. Include the component and its version, the steps to reproduce the issue, and what an attacker could do with it. Proof-of-concept code helps.
What we commit to
- Acknowledgement of your report within two business days.
- Updates while we investigate and fix it.
- Credit by name, if you want it.
Safe harbor
We will not pursue legal action over research done in good faith under this policy. Good faith means three things.
- Test only what you run. Latent runs inside customers' environments. Use your own install, and never test a deployment you do not own.
- Take only what you need. Access no more data than it takes to show the issue, and keep none of it.
- Do no harm. Avoid anything that degrades a service or damages data.