Security

Practical controls, stated without inflated guarantees.

This page describes controls used by the Innovix marketing website and the security approach applied to scoped product work. It is not a certification, penetration-test report, service-level agreement, or compliance attestation.

Updated: July 23, 2026

Minimize what the website collects

The lead forms ask for information needed to respond to a beta request or product-sprint inquiry. They instruct visitors not to submit credentials or other sensitive information, and form consent does not enroll a visitor in marketing.

Validate and limit public submissions

Lead submissions are validated on the server and pass honeypot and hashed-request rate-limit checks before a lead is stored or a notification is attempted.

Keep credentials and lead access server-side

Storage, rate-limit, and notification credentials are read from the server environment. Direct anonymous access to the lead table is revoked, and the approved server path requires a separate high-entropy secret.

Constrain the browser-facing surface

The production site is served over HTTPS and uses a content security policy that limits scripts, frames, forms, images, connections, and other browser-loaded resources to the sources needed by the website.

Preserve a lead when notification fails

A valid lead is written before the notification email is sent. If email delivery fails, the lead remains stored and the notification status records the failure for follow-up.

Review security against the product boundary

For a product-engineering sprint, Innovix identifies the data flow, external services, access needs, misuse cases, and failure modes that belong to the agreed product scope.

Service providers and shared responsibility

Vercel hosts the website, Supabase stores lead records and supports rate-limit operations, Resend sends notifications, and Google provides analytics. Those services operate parts of the infrastructure under their own security programs. Innovix configures and uses them for this site but does not represent their controls as Innovix certifications.

Visitors also share responsibility for using a supported browser, protecting their own systems and accounts, avoiding sensitive information in inquiry forms, and reporting suspicious behavior through the channel below.

Limits, changes, and product-specific practices

No internet service can guarantee that every defect, interruption, or security event will be prevented. Controls can change as the website, providers, and risk profile change. Talos, Vspoke, and future products may publish additional product-specific security or privacy information where their data flows differ from this marketing website.

Report a concern

Give us enough detail to investigate.

Include the affected page or product, what you observed, when it occurred, and safe reproduction details. Do not include passwords, private keys, personal data, live exploit payloads, or confidential customer material in the initial email.

Innovix will use the contact information you provide to review and follow up on the report. No specific response or remediation deadline is promised on this public page.

Email a security report