Security
at INAT Labs.
Found a problem? Tell us. We'll fix it, and we won't come after you for looking.
Last updated: October 5, 2026
How Productive protects your team
Two-factor sign-in is required for every account. Each team's data is kept separate from every other team's. Sign-in tokens and secrets are stored only in hashed or encrypted form. Every important change is recorded in an activity log that your admins can check for tampering.
Report a vulnerability
Email hello@theinatlabs.com with "Security" in the subject. Tell us what you found and where, how to reproduce it with your own test account, and what someone could do with it.
We acknowledge reports within 3 business days and send a status update at least every 2 weeks. We aim to fix critical issues within 14 days and others within 90 days. With your permission, we credit you when the fix is published.
Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorized and will not pursue or support legal action against you. Good faith means you:
- test only with accounts and data you own or have permission to use;
- stop once you've shown the problem: don't access, change or keep other people's data, and don't disrupt the service;
- don't use social engineering, phishing or physical attacks;
- give us reasonable time to fix the issue before disclosing it. We'll agree a date with you, normally within 90 days.
Scope
In scope: Productive (productive.theinatlabs.com and its API) and theinatlabs.com. Out of scope: third-party services we use (please report those to their owners), and attacks that need a compromised device.
After a fix
We publish a short advisory for issues that affected customers, listing the weakness type (CWE), what was affected, and the fix. A machine-readable version of this policy is at /.well-known/security.txt.