Vulnerability Disclosure Policy
One policy, all surfaces. It covers:
- MOD SaaS — the hosted multi-tenant service (API, Dashboard, Workflow Builder, workers, node images, billing and license endpoints).
- MOD on-prem — the full self-hosted install (API, orchestrator, Go worker, WorkflowBuilder, Dashboard, and the node images maintained in the MOD Core repo).
- MOD Core (Community Edition) — the open-source codebase and its releases.
- Our public websites — the modtechlabs.com marketing site and this documentation site.
Report through the channel below regardless of which surface is affected — one mailbox routes everything.
Out of scope
These are out of scope. If you believe you have found a real issue in one of them anyway, write to us — we will triage it and tell you plainly if it is not something we can act on.
- Denial-of-service attacks.
- Social engineering, phishing, or pretexting.
- Physical attacks or data-center access.
- Vulnerabilities in third-party services and dependencies (report upstream; a heads-up is welcome so we can track the fix).
- Issues already known and being addressed, or that require access you do not legitimately hold.
How to report
Email security@modtechlabs.com. Do not report security
vulnerabilities through public GitHub issues, discussions, or pull requests.
To speed triage, include, where applicable:
- A description of the vulnerability and its potential impact.
- The affected product, version, and environment (SaaS, on-prem, or CE).
- Steps to reproduce, or a proof-of-concept (see the safe-harbor rules below).
- Any known mitigations or workarounds.
We also accept an encrypted report on request — ask in your initial email and we will reply with a PGP key or an encrypted upload link.
What you can expect from us
- Acknowledgment: within 3 business days of your report.
- Triage: an initial assessment within 10 days, including a severity estimate and whether it is accepted as a valid issue.
- Coordinated disclosure: we target resolution and a coordinated public disclosure within 90 days of confirmation — extendable by mutual agreement when a fix needs more time.
- Credit: with your permission, we credit you in the release notes or security advisory. Anonymous credit is fine too.
Security fixes ship as normal patch releases and are announced in the release notes of the affected product.
Good-faith safe harbor
We will not take legal action against a researcher who:
- Reports through this policy in good faith.
- Avoids accessing, copying, or exfiltrating data that is not yours — do not access other tenants' data; use your own accounts and your own install.
- Avoids destroying data or interrupting service, and stops at a proof of concept rather than exploiting the vulnerability further than needed to demonstrate it.
Where this policy conflicts with a website's or product's terms of service, this policy governs good-faith security research.
Supported versions
MOD Core (CE) is pre-1.0 and moves quickly: security fixes land on the
main branch and ship in the next release, and older tagged releases are not
supported until a 1.0 line with defined support windows exists. For SaaS and
on-prem, the supported version is always the latest patch level — we will
help you move to it when you report.
Plain about claims: this policy supports the security process described here. It does not claim that any MOD product meets or is validated against any standard.