Security and Abuse Reporting

Last updated: 3 August 2026

Security and Abuse Reporting

Security vulnerabilities, suspected credential compromise, unlawful use and serious abuse should be reported to [email protected].

Include in Your Report

  • a clear description of the issue;
  • affected URL, endpoint or feature;
  • reproduction steps;
  • relevant dates and request identifiers;
  • the likely impact; and
  • safe supporting evidence.

Do Not Include

  • passwords;
  • full private API keys;
  • complete payment-card details;
  • one-time authentication codes;
  • private cryptographic keys; or
  • unnecessary personal or illegal content.

Responsible Conduct

Do not access data belonging to others, disrupt production, conduct denial-of-service testing, install persistence, alter records or publicly disclose an unresolved vulnerability.

Security testing requires prior written authorisation. Submission of a report does not create a right to payment or a bug bounty.

Response

Model Gate will review credible reports and may request additional information. Response and remediation times depend on severity, complexity, provider dependencies and verification.

Law-Enforcement Requests

Official legal requests should be sent to [email protected] from an identifiable official address and must state the legal authority, scope and applicable deadline.