Standard Compute · Vulnerability Disclosure
Standard Compute Vulnerability Disclosure
Vulnerability disclosure
Standard Compute publishes a vulnerability disclosure policy for reporting security issues.
llm apiflat-ratesubscriptionai agentsinferencemodel routingai gatewaydeveloper toolscoding agentsopenai-compatible
Program:
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-02'
method: searched
probe: true
source: https://standardcompute.com/security
program:
published: true
type: responsible disclosure (no bug bounty)
bounty: false
bounty_platform: null
contact_email: contact@standardcompute.com
submission_channel: email
required_report_contents:
- detailed description of the vulnerability
- steps to reproduce
- supporting evidence
response_commitments:
acknowledgement: within 2 business days
initial_assessment: within 7 business days
ongoing: keeps the reporter informed of remediation progress
safe_harbor:
offered: true
text: >-
"We will not take legal action against researchers who report vulnerabilities
in good faith and do not access other users' data or disrupt the service."
conditions:
- good-faith reporting
- no access to other users' data
- no disruption of the service
security_txt:
served: false
probed:
- url: https://standardcompute.com/.well-known/security.txt
status: 404
- url: https://api.stdcmpt.com/.well-known/security.txt
status: 404
note: >-
The policy exists and meets RFC 9116's substance — a contact, a policy page,
stated response times and safe harbour — but the machine-readable file is not
served. Publishing /.well-known/security.txt with Contact:
mailto:contact@standardcompute.com and Policy:
https://standardcompute.com/security would be a five-minute fix.
published_security_practices:
api_key_encryption: AES-256-GCM at rest, per-account derived key stored separately
key_visibility: plaintext shown once at creation; only an encrypted blob plus last four characters retained
key_recovery: none — provider states no administrative path to recover plaintext
request_authentication: HMAC-SHA256 with constant-time comparison
brute_force_control: failed authentication attempts rate limited
transport: TLS 1.2+, Mozilla Intermediate profile, plaintext HTTP refused (not redirected)
database_isolation: row-level security policies enforced in the database engine, tested by cross-account integration tests
prompt_logging: >-
None. Prompt and response content is not logged, stored or inspected on any
plan, and the provider states there is no analytics or debugging mode that
enables it. Only metadata — timestamp, model identifier, token count — is
retained, for usage tracking and fair-use enforcement.
upstream_isolation: >-
Per-provider TLS with dedicated service credentials; credentials for one upstream
cannot access another. The routing pool spans multiple providers and countries,
so the jurisdiction handling a request can vary.
training_on_customer_data: >-
Standard Compute does not train its own models on customer prompts or outputs.
It explicitly declines to warrant upstream providers' training policies and tells
compliance-bound buyers to read the upstream provider's own terms.
evidence:
- source: https://standardcompute.com/security
status: 200
fetched: '2026-09-02'
kind: disclosure page
keywords:
- vulnerability
- responsible disclosure
- safe harbor
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/standard-compute-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.