Report a vulnerability
Email security@modulate.ai. Reports are accepted from anyone, at any time. No account, contract, or prior relationship with Modulate is required.Bugs, integration questions, and billing issues that are not security vulnerabilities go to support, which routes them to the right team.
Authorization for good-faith research
Modulate authorizes good-faith security research against the systems listed under Scope, and will not pursue or support legal action against researchers who follow this policy. For research conducted in a good-faith effort to comply with this policy, Modulate will:- Consider the research authorized, and not initiate or recommend legal action against the researcher for it.
- Not report the activity to law enforcement on the basis of the research itself.
- Work with the researcher to understand and resolve the issue.
To confirm whether a specific test is authorized, email security@modulate.ai before running it.
Scope
In scope
- The documentation site,
docs.modulate.ai - The developer platform,
platform.modulate.ai - The Velma model APIs served from
platform.modulate.ai/api/*
Out of scope
This policy does not authorize:- Denial-of-service testing, load testing, or any activity that degrades service for other users.
- Social engineering, phishing, or physical attacks against Modulate staff, users, or facilities.
- Automated scanning that generates high request volume against production endpoints.
- Testing of systems not listed as in scope. If a system outside this list appears to be affected, report it by email rather than testing it.
- Findings that require a compromised account, device, or network to exploit.
- Output from automated tooling with no demonstrated security impact.
What a report contains
Include the name or handle to credit, if credit is wanted. Reports in English are preferred.
Response commitments
An incomplete report is not closed silently. Modulate replies asking for the missing detail.
Coordinated disclosure
Modulate requests 90 days from acknowledgement of a report before public disclosure, so that a fix is available to customers before the details are. If a complex fix needs longer, Modulate explains why and agrees a revised date with the researcher.This policy does not ask for indefinite confidentiality, and authorization of research is not conditional on agreeing never to publish. After the agreed period, the researcher is free to disclose the findings publicly. Modulate prefers to coordinate the timing and content of that disclosure with the researcher.
Rules of engagement
Research under this policy must:- Cause no harm. Stop once the vulnerability is demonstrated. Do not degrade, disrupt, or damage Modulate systems or the service other users depend on.
- Not use a vulnerability to gain unauthorized access. Do not pivot, escalate privileges, or move laterally beyond what is needed to prove the finding.
- Not access, modify, delete, or retain data belonging to others. On encountering customer data, personal information, or credentials, stop, and describe what was encountered in the report.
- Not exfiltrate data. Demonstrating access is sufficient.
- Use test accounts and test data under the researcher’s control wherever possible.
- Allow time to remediate before disclosure, as set out in Coordinated disclosure.