generated: '2026-09-18' method: searched source: https://modal.com/docs/guide/security provider: Modal providerId: modal-labs description: >- Modal publishes a vulnerability remediation policy with named severity timeframes and runs a PRIVATE bug bounty programme through HackerOne that you join by emailing security@modal.com. There is no /.well-known/security.txt on any Modal host — the policy lives in the docs, not at the RFC 9116 path. contact: email: security@modal.com url: https://modal.com/docs/guide/security policy_url: https://modal.com/docs/guide/security security_txt: null security_txt_note: >- Probed /.well-known/security.txt on modal.com, www.modal.com, api.modal.com and oidc.modal.com on 2026-09-18 — 404, 404, gRPC catch-all and 403 respectively. No RFC 9116 document is served. bug_bounty: platform: HackerOne url: https://modal.com/docs/guide/security public: false note: >- "We currently run a private bug bounty program through HackerOne. If you have found a vulnerability and wish to participate, please send an email to security@modal.com with your HackerOne username or email and we will invite you to the program." Invitation-only; no public programme page. remediation: severity_basis: CVSS severity_note: >- "If there is a CVSS severity rating accompanying a vulnerability disclosure, we rely on that as a starting point, but may upgrade or downgrade the severity using our best judgement." timeframes: - severity: Critical target: 24 hours - severity: High target: 1 week - severity: Medium target: 1 month - severity: Low target: 3 months - severity: Informational target: 3 months or longer practices: - External penetration testing firms engaged to assess the platform. - Annual business continuity and security incident exercises. - gVisor container sandboxing (the runtime Google uses for Cloud Run and GKE). maintainers: - FN: Kin Lane email: kin@apievangelist.com