> ## Documentation Index
> Fetch the complete documentation index at: https://docs.modulate.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability disclosure policy

> How to report a security vulnerability to Modulate, what a report contains, Modulate's response commitments, and the authorization extended to good-faith security research.

Modulate takes the security of its systems and its customers' data seriously, and accepts vulnerability reports from security researchers, customers, and members of the public.

## Report a vulnerability

Email [security@modulate.ai](mailto:security@modulate.ai).

Reports are accepted from anyone, at any time. No account, contract, or prior relationship with Modulate is required.

<Note>
  Bugs, integration questions, and billing issues that are not security vulnerabilities go to [support](/support), which routes them to the right team.
</Note>

## Authorization for good-faith research

Modulate authorizes good-faith security research against the systems listed under [Scope](#scope), and will not pursue or support legal action against researchers who follow this policy.

For research conducted in a good-faith effort to comply with this policy, Modulate will:

* Consider the research authorized, and not initiate or recommend legal action against the researcher for it.
* Not report the activity to law enforcement on the basis of the research itself.
* Work with the researcher to understand and resolve the issue.

Good faith means following the [rules of engagement](#rules-of-engagement), reporting findings promptly, and not using a vulnerability beyond what is necessary to demonstrate it.

If a third party initiates legal action against a researcher for activity that complied with this policy, Modulate will make this authorization known.

<Note>
  To confirm whether a specific test is authorized, email [security@modulate.ai](mailto:security@modulate.ai) before running it.
</Note>

## Scope

### In scope

* The documentation site, `docs.modulate.ai`
* The developer platform, `platform.modulate.ai`
* The Velma model APIs served from `platform.modulate.ai/api/*`

### Out of scope

This policy does not authorize:

* Denial-of-service testing, load testing, or any activity that degrades service for other users.
* Social engineering, phishing, or physical attacks against Modulate staff, users, or facilities.
* Automated scanning that generates high request volume against production endpoints.
* Testing of systems not listed as in scope. If a system outside this list appears to be affected, report it by email rather than testing it.

Modulate does not accept as vulnerabilities:

* Findings that require a compromised account, device, or network to exploit.
* Output from automated tooling with no demonstrated security impact.

Vulnerabilities in third-party services that Modulate uses but does not operate go to that third party. If the exposure affects Modulate data, report it to Modulate as well.

## What a report contains

| Field | Contents |
| - | - |
| **Issue type** | The class of vulnerability: injection, authentication bypass, exposed credential, access-control flaw, or similar. |
| **Path to issue** | The affected component, service, or code path. |
| **Location** | The exact URL, endpoint, or host where the issue appears. |
| **Steps to reproduce** | A numbered sequence that reproduces the issue, including any required request headers, parameters, or account state. |
| **Proof of concept** | A request, script, screenshot, or capture demonstrating the issue, if available. |
| **Impact** | What an attacker could achieve, and the path to exploitation. |

Include the name or handle to credit, if credit is wanted. Reports in English are preferred.

<Warning>
  Do not include live customer data, credentials, or personal information in a report. If a vulnerability exposed such data, describe what was reachable and how, without attaching it. If a copy has already been retained, say so in the report and Modulate will provide disposal instructions.
</Warning>

## Response commitments

| Stage | Commitment |
| - | - |
| **Acknowledgement** | Every complete report is acknowledged within **1 business day**. |
| **Investigation** | In-scope reports with enough detail to act on are investigated. Modulate sends an initial investigation update, including whether the issue was reproduced where reproduction is possible, normally within **10 business days** of acknowledgement. |
| **Remediation timeline** | Once an issue is validated, Modulate gives an estimated remediation timeline where one can reasonably be given, and confirms when the remediation is complete or deployed. |
| **Progress updates** | Modulate sends updates at meaningful milestones and, while a validated issue is unresolved, at least every **10 business days**, so researchers do not have to ask for status. |

An incomplete report is not closed silently. Modulate replies asking for the missing detail.

## Coordinated disclosure

Modulate requests **90 days** from acknowledgement of a report before public disclosure, so that a fix is available to customers before the details are. If a complex fix needs longer, Modulate explains why and agrees a revised date with the researcher.

<Note>
  This policy does not ask for indefinite confidentiality, and authorization of research is not conditional on agreeing never to publish. After the agreed period, the researcher is free to disclose the findings publicly. Modulate prefers to coordinate the timing and content of that disclosure with the researcher.
</Note>

If an issue is being actively exploited, or a fix is delayed past the agreed date, contact [security@modulate.ai](mailto:security@modulate.ai) to agree a disclosure plan.

## Rules of engagement

Research under this policy must:

* **Cause no harm.** Stop once the vulnerability is demonstrated. Do not degrade, disrupt, or damage Modulate systems or the service other users depend on.
* **Not use a vulnerability to gain unauthorized access.** Do not pivot, escalate privileges, or move laterally beyond what is needed to prove the finding.
* **Not access, modify, delete, or retain data belonging to others.** On encountering customer data, personal information, or credentials, stop, and describe what was encountered in the report.
* **Not exfiltrate data.** Demonstrating access is sufficient.
* **Use test accounts and test data under the researcher's control** wherever possible.
* **Allow time to remediate** before disclosure, as set out in [Coordinated disclosure](#coordinated-disclosure).

Requests to the Models API spend credits from the organization that owns the API key, including requests made during research.

## Credit

On request, Modulate credits the researcher by name or handle when the fix is released. Researchers who prefer to remain anonymous are not named, and no researcher is named without their agreement.

This is a disclosure program, not a paid bounty program. Modulate does not currently offer monetary rewards for reports.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.