Security
How to report a vulnerability in OfflinAI's software, what we commit to, and how security fixes reach you.
Found a vulnerability?
Email [email protected]. We acknowledge every report within three business days. Machine-readable details: security.txt.
Reporting a vulnerability
Email [email protected] and include, as far as you can:
- the product and its version (shown on the console's overview page, or by
offlinai-server --version); - what you found, and what an attacker could do with it;
- the steps to reproduce it, with any proof of concept;
- whether you know of it being exploited.
If the details are sensitive, send a short first message without them and we will agree a secure way to share them. Please test only installations that you own or are allowed to test, do not access or change other people's data, and give us reasonable time to fix the problem before you make it public.
What we commit to
- An acknowledgement within three business days of your report.
- Progress updates while we investigate, including our assessment of how serious the problem is.
- Coordinated disclosure: we agree the publication date with you. We fix serious problems as fast as we can, normally within 90 days.
- Credit in the release notes and the advisory, if you would like it.
- No legal action against research done in good faith and in line with this page.
We do not run a paid bug-bounty programme.
How security fixes reach you
Security fixes are published as new releases as soon as they are ready, with release notes that say what was fixed and how serious it is.
- Free of charge for the whole support period. Every licence holder receives security fixes free of charge for five years from the date of purchase. A perpetual licence keeps receiving them after its twelve months of new features end. The Free plan receives the same fixes in the same releases.
- Actively exploited vulnerabilities. If a vulnerability in our software is being actively exploited, we report it to the EU's cybersecurity authorities as the Cyber Resilience Act requires, and we tell affected customers what to do.
- Advisories are listed at the end of this page.
What OfflinAI Server sends us
Your prompts, documents and outputs stay on your machines; we never receive them. The Free plan sends us nothing.
To activate a paid plan and keep it active, the server sends our licence service the licence key, a pseudonymous identifier of the machine, its host name, its operating system and the server's version, and it refreshes the licence from time to time. A server without internet access uses an offline licence file instead. The server contacts other services only when you use a feature that needs them, such as model downloads, cloud model providers, certificate authorities or audit forwarding that you configure. Section 5 of the OfflinAI Server Licence and our Privacy Policy describe this in full.
Supply chain
- Official sources: the container image offlinai/offlinai-server on Docker Hub, and the packages that OfflinAI sends you or links from offlinai.com.
- Third-party notices for every open-source component ship inside every package and image.
- Dependencies are checked against published vulnerability databases before every release.
- From release 0.2: Windows packages signed with OfflinAI Limited's code-signing certificate, a software bill of materials (SBOM, CycloneDX) with every release, and the SHA-256 digests of the packages and images in the release notes.
Advisories
No security advisories have been published.
Security reports: [email protected] · Everything else: [email protected]
OfflinAI Limited, 2 Stockwell, Sandyford Road, Dublin 16, Ireland
Last updated: 11 October 2026