Responsible Disclosure
We welcome reports from security researchers. If you've found a vulnerability in ModelCop, tell us — we'll work with you to confirm and fix it.
How to report
Email security@modelcop.ai with a description of the issue, the affected component or URL, and steps to reproduce. A PGP key is available on request for sensitive reports.
What to expect
- We acknowledge reports within one business day.
- We provide a status update at least every 7 days until the issue is resolved.
- We'll credit you for the discovery if you wish, once a fix is shipped.
Scope
- In scope: the ModelCop platform, console, and public website.
- Out of scope: third-party services we integrate with (report those to the respective vendor), social engineering, physical attacks, and denial-of-service testing.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, will not pursue legal action against you, and will work with you to understand and resolve the issue quickly. Please act in good faith: don't access or modify data that isn't yours, don't degrade the service, and give us reasonable time to remediate before any public disclosure.
Out of scope at this stage
We do not currently operate a paid bug-bounty program. We deeply appreciate responsible reports and will acknowledge contributors.