Security
Security & responsible disclosure
ModelStrike takes security seriously — including our own. If you believe you've found a vulnerability in a ModelStrike system, we want to hear about it.
How to report
A dedicated security contact address will be published here. Until then, please use the contact form to request a secure channel, without including vulnerability details in the initial message.
Scope
- This website and its contact form
- Any other ModelStrike-operated domain or service
Third-party services we use are covered by their own disclosure policies.
Guidelines
- Only test against systems you are authorized to test, and avoid accessing, modifying, or deleting data that isn't yours.
- Do not run denial-of-service, spam, social engineering, or physical attacks.
- Give us reasonable time to investigate and remediate before any public disclosure.
- Include enough detail for us to reproduce the issue: affected URL, steps, and potential impact.
Our commitments
- Acknowledge your report and keep you informed as we investigate.
- Not pursue legal action against good-faith research that follows these guidelines.
- Credit you for the discovery if you'd like, once the issue is resolved.
ModelStrike does not currently operate a paid bug bounty program.