Modal · Vulnerability Disclosure

Modal Labs Vulnerability Disclosure

Vulnerability disclosure

Modal publishes a vulnerability remediation policy with named severity timeframes and runs a PRIVATE bug bounty programme through HackerOne that you join by emailing security@modal.com. There is no /.well-known/security.txt on any Modal host — the policy lives in the docs, not at the RFC 9116 path.

Modal runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

ServerlessComputeGPUAI InfrastructureSandboxInfrastructure as Code
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@modal.com
Contact
urlhttps://modal.com/docs/guide/security

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-18'
method: searched
source: https://modal.com/docs/guide/security
provider: Modal
providerId: modal-labs
description: >-
  Modal publishes a vulnerability remediation policy with named severity
  timeframes and runs a PRIVATE bug bounty programme through HackerOne that you
  join by emailing security@modal.com. There is no /.well-known/security.txt on
  any Modal host — the policy lives in the docs, not at the RFC 9116 path.
contact:
  email: security@modal.com
  url: https://modal.com/docs/guide/security
policy_url: https://modal.com/docs/guide/security
security_txt: null
security_txt_note: >-
  Probed /.well-known/security.txt on modal.com, www.modal.com, api.modal.com
  and oidc.modal.com on 2026-09-18 — 404, 404, gRPC catch-all and 403
  respectively. No RFC 9116 document is served.
bug_bounty:
  platform: HackerOne
  url: https://modal.com/docs/guide/security
  public: false
  note: >-
    "We currently run a private bug bounty program through HackerOne. If you have
    found a vulnerability and wish to participate, please send an email to
    security@modal.com with your HackerOne username or email and we will invite
    you to the program." Invitation-only; no public programme page.
remediation:
  severity_basis: CVSS
  severity_note: >-
    "If there is a CVSS severity rating accompanying a vulnerability disclosure,
    we rely on that as a starting point, but may upgrade or downgrade the
    severity using our best judgement."
  timeframes:
  - severity: Critical
    target: 24 hours
  - severity: High
    target: 1 week
  - severity: Medium
    target: 1 month
  - severity: Low
    target: 3 months
  - severity: Informational
    target: 3 months or longer
practices:
- External penetration testing firms engaged to assess the platform.
- Annual business continuity and security incident exercises.
- gVisor container sandboxing (the runtime Google uses for Cloud Run and GKE).
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/modal-labs-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.