← All legal documents

Infinitus / Legal

Security Policy

Infinitus runs coding agents on your own machine, so security is genuinely shared: I secure the software and the small amount of infrastructure I operate, and you secure the devices, credentials and environments you connect. This explains how to report a vulnerability and what to expect.

Effective
2026-09-17
Last updated
2026-09-17

01

Scope

This policy covers the Infinitus applications for macOS, desktop, Linux and iOS, the website at https://infinitus.run, and the optional relay at relay.infinitus.run.

Infinitus connects software on your devices to coding-agent harnesses and providers you choose. I secure what I write and operate; I do not control your devices, environments, repositories, networks, credentials or third-party providers. Vulnerabilities in a third-party provider should go to that provider. Infinitus is a fork of T3 Code — a flaw inherited from upstream is still worth reporting here, and I will coordinate with upstream where appropriate.

02

Reporting a Vulnerability

Two private channels, either is fine:

Please do not open a public issue or disclose publicly until there has been a reasonable opportunity to investigate and fix the problem.

Include, where you can:

  • What the issue is and what an attacker could do with it;
  • The affected application, version, URL, endpoint or component;
  • Reproduction steps or a minimal proof of concept;
  • Relevant logs or request and response details, with secrets removed; and
  • How you would like to be contacted, and whether you want public credit.

What to expect. Infinitus is maintained by one person. I aim to acknowledge a complete report within a few days, to keep you informed as things move, and to coordinate disclosure once a fix is available. Fix time depends on severity, complexity and on upstream or third-party dependencies. There is no bug-bounty program and no payment for reports.

03

Responsible Research and Safe Harbor

Good-faith security research is welcome. If you make a genuine effort to follow this policy, avoid harm, respect privacy and report promptly, I will treat your research as authorized and will not pursue legal action against you for accidental, good-faith violations of this policy. If a third party takes action over research that complied with this policy, I will make that authorization known where appropriate.

To stay within this safe harbor:

  • Test only accounts, data and systems you own or have explicit permission to test;
  • Stop and report immediately if you encounter anyone else's personal or confidential data;
  • Access only the minimum needed to demonstrate the issue;
  • Do not disrupt availability, degrade performance, or damage or delete data;
  • No social engineering, phishing, physical attacks or denial-of-service testing;
  • Do not test third-party services or infrastructure outside my control; and
  • Give reasonable time to fix the issue before disclosing it publicly.

This safe harbor does not authorize breaking the law or acting outside the scope of this policy.

04

Security Practices

What the project actually does, rather than what would sound reassuring:

  • Local by default. Session content stays between your clients, your machine and the providers you configure. Publisher-operated infrastructure is involved only in features you turn on, and even then carries notification metadata rather than your code or prompts.
  • Credential storage. Credentials and session tokens use the platform keychain where available. Secrets are passed over standard input rather than command-line arguments, where they would be visible in the process table, and are shown masked in the interface.
  • Encrypted transport. Network services use encrypted transport. Connection flows use scoped, proof-bound tokens designed to resist replay, and authorization headers are redacted from diagnostics.
  • Local control socket. The Mac app and the server communicate over a local socket, not an exposed network port.
  • No telemetry by default. The shipped applications send no analytics. Relay diagnostics exist to operate the relay, and expire.
  • Open source. Every line is public at github.com/deathemperor/infinitus. You can read exactly what it does rather than take this page's word for it, and dependency updates and fixes land in public commits.

No system is completely secure. These practices reduce risk; they do not guarantee the absence of vulnerabilities. Infinitus is alpha software maintained by one person — weigh that when deciding what to connect it to.

05

Your Responsibilities

You control most of the execution path, and Infinitus runs agents that can read, write and execute on your machine. That makes the following genuinely important:

  • Keep Infinitus, your operating system and your connected tools up to date;
  • Secure your devices, repositories, environments, networks and backups;
  • Protect provider, repository and environment credentials;
  • Use multi-factor authentication wherever your providers support it;
  • Grant providers and integrations only the permissions they need;
  • Review commands, source changes and other agent output before applying or executing it — this is the single most effective control you have;
  • Be deliberate about exposing an environment through a tunnel, and close it when done;
  • Remove lost or unused devices and revoke credentials you believe may be compromised.

Never include passwords, API keys, access tokens or private keys in a vulnerability report. Revoke anything that may have been exposed before sending sanitized evidence.

06

Updates to This Policy

This policy may be updated as Infinitus and its infrastructure evolve. Revisions are posted at this URL with the dates above updated. Material changes to the reporting process or safe-harbor terms apply going forward.

07

Contact

Security reports: private vulnerability reporting or deathemperor@gmail.com.

Privacy requests and general legal questions go to the same address — see the Privacy Policy and Terms of Service.

infinitus.run · Legal · GitHub