Draft — pending legal review
This text describes how the testnet service works today. It has not been reviewed by counsel yet and may change before any mainnet launch.
Security policy
Last updated 4 October 2026.
We welcome reports of vulnerabilities in Inferit. This page says what is in scope and how we treat good-faith research.
Please do not open a public issue or post details of a vulnerability before we have had a reasonable chance to fix it (we suggest 90 days, or sooner once a fix is live). There is no paid bug bounty at this stage.
Scope
In scope:
- The MarketEscrow and TestCredit contracts on Whitechain Sepolia (addresses on the Whitechain escrow page), especially any way to move funds outside the bounds described in Security & trust.
- The Inferit API: authentication, API keys, sessions, routing, metering and settlement.
- The x402 facilitator and the sponsored testnet faucet (Pay per request with x402): any way to be served without paying, to replay or redirect a payment, to credit a payment to anyone but its signer, or to make the facilitator key spend gas on payments that never verify.
- This website, including the wallet flows and what the site asks your wallet to sign.
- The seller node software, and anything that would let one party learn what the API promises not to publish.
Out of scope:
- Third-party services: the Whitechain network, RPC, explorer and faucet, wallets, and our hosting providers. Report those to their operators.
- Denial of service, volumetric or load testing, and spam.
- Social engineering, phishing or physical attacks against people.
- Issues that need a compromised device or browser, or that only affect outdated browsers.
- Missing headers or best-practice notes without a demonstrated impact.
- The fact that settlement data is public on-chain; that is by design.
Safe harbor
If you research in good faith and follow this policy, we consider your research authorised, will not pursue or support legal action against you for it, and will work with you to understand and fix the issue. Good faith means you:
- use only testnet tokens and accounts and wallets you control;
- do not access, change or keep other people's data beyond the minimum needed to show the issue;
- do not degrade the service for others, and stop if you reach data that is not yours;
- give us reasonable time to fix the issue before disclosing it.
Terms of use · Privacy · Acceptable use · Security · About