Security

Last updated: August 25, 2026

Reporting a vulnerability

If you believe you have found a security vulnerability in Modelence, email [email protected] with enough detail for us to reproduce the issue. We read every report and will respond to legitimate ones.

We ask that you act in good faith: do not access or modify data that is not yours, do not disrupt the Services, and give us a reasonable opportunity to fix the issue before disclosing it publicly. We will not pursue legal action over good-faith research that follows these rules.

No bug bounty program

We do not operate a bug bounty program and do not pay rewards, fees, or compensation of any kind for vulnerability reports. Requests for payment, including "goodwill" or "appreciation" payments, will not receive a response.

Out of scope

The following are not vulnerabilities and reports about them will not receive a response: missing security headers without a demonstrated impact, SPF, DKIM, or DMARC configuration opinions, clickjacking on pages with no sensitive actions, software version disclosure, unmodified output from automated scanners, and denial-of-service or social-engineering findings.