Security

How to report a vulnerability in OfflinAI's software, what we commit to, and how security fixes reach you.

Found a vulnerability?

Email [email protected]. We acknowledge every report within three business days. Machine-readable details: security.txt.

Report it

Reporting a vulnerability

Email [email protected] and include, as far as you can:

If the details are sensitive, send a short first message without them and we will agree a secure way to share them. Please test only installations that you own or are allowed to test, do not access or change other people's data, and give us reasonable time to fix the problem before you make it public.

What we commit to

We do not run a paid bug-bounty programme.

How security fixes reach you

Security fixes are published as new releases as soon as they are ready, with release notes that say what was fixed and how serious it is.

What OfflinAI Server sends us

Your prompts, documents and outputs stay on your machines; we never receive them. The Free plan sends us nothing.

To activate a paid plan and keep it active, the server sends our licence service the licence key, a pseudonymous identifier of the machine, its host name, its operating system and the server's version, and it refreshes the licence from time to time. A server without internet access uses an offline licence file instead. The server contacts other services only when you use a feature that needs them, such as model downloads, cloud model providers, certificate authorities or audit forwarding that you configure. Section 5 of the OfflinAI Server Licence and our Privacy Policy describe this in full.

Supply chain

Advisories

No security advisories have been published.

Security reports: [email protected] · Everything else: [email protected]
OfflinAI Limited, 2 Stockwell, Sandyford Road, Dublin 16, Ireland

Last updated: 11 October 2026