INPUTLAG / INFORMATION

Security at InputLag

How access is controlled, how Windows changes are applied, and how to report a concern.

Updated September 11, 2026

Account and paid access

The website uses Supabase authentication. Protected server endpoints check authentication and authorization before handling privileged operations. Subscription and license access is checked on the server; hiding a button is not the access-control mechanism.

Stripe checkout and the customer portal handle subscription payment flows. Stripe webhook events update subscription access. Never send support your password, full card details or authentication tokens.

Windows helper service

Some optimizations require an elevated Windows helper. The desktop interface communicates through a restricted bridge, and the helper handles registered actions rather than arbitrary commands from the interface. Helper requests use HMAC authentication.

System changes can affect device behavior. Backup and restore support depends on the action; review it before proceeding. These controls reduce risk but do not guarantee that every action is suitable for every PC.

License protection

License activation includes server-side validation, attempt logging, rate limits and lockouts for repeated suspicious attempts. Keep unused keys private and activate them only through InputLag’s account or app flows.

Protect your setup

Download the Windows client through the official InputLag website. Keep Windows and the app updated, protect your email account, and review the requested permissions before applying changes. Avoid sharing account sessions, license keys or unredacted logs publicly.

Report a vulnerability

Email support with a description, the affected page or app version, steps to reproduce and the potential impact. A minimal, redacted example is enough to start. Do not include credentials or other users’ personal information.

Test only accounts and devices you control. Do not access others’ data, disrupt service or exploit an issue beyond what is needed to demonstrate it. If you encounter another person’s information, stop and report the issue privately. This page does not promise a bounty or a fixed response time.

Scope of this page

This is an overview of controls implemented in the product, not a certification or an independent security audit. No online service or system utility can guarantee absolute security. Contact support about a suspected account compromise or unexpected system change.

Contact

Inputlag OÜ
Registry code: 17592766 · Estonia

Legal and privacy enquiries: info@inputlag.app
Support and vulnerability reports: support@inputlag.app