How we protect your account and data
Security practices for the platform hosting your models, datasets, and Spaces.
Encryption in transit
All traffic to inferix.co is served over HTTPS/TLS. Internal service-to-service traffic runs on a private network.
Password and token security
Passwords are hashed with bcrypt, never stored in plaintext. Sessions use short-lived JWT access tokens with rotating refresh tokens.
Hardened API surface
The API sits behind security headers (Helmet), per-endpoint rate limiting, and CAPTCHA challenges on auth flows to blunt abuse and credential-stuffing attempts.
Access control by default
Private repositories, gated models, and organization resources are checked against the requesting user's membership and role on every request — not just at the UI layer.
Found a security issue?
Report vulnerabilities responsibly — we'll acknowledge and investigate genuine reports.