generated: '2026-09-10' method: searched source: https://github.com/Moonveil-AI/modelrush-developer-tools/blob/main/SECURITY.md note: ModelRush publishes a vulnerability disclosure policy as the SECURITY.md of its official Moonveil-AI/modelrush-developer-tools repository (fetched 2026-09-10, raw.githubusercontent.com returned 200). It is repo-scoped rather than a domain-level program -- no /.well-known/security.txt is served on modelrush.ai, www.modelrush.ai, or api.modelrush.ai (all 404, see well-known/modelrush-well-known.yml), and no bug bounty program was found on HackerOne, Bugcrowd, or Intigriti. The docs security page (https://modelrush.ai/docs/policies/security, "Security and data boundaries") covers integrator-side key/data/abuse boundaries but names no disclosure channel. policy: channel: email contact: mailto:info@modelrush.ai policy_url: https://github.com/Moonveil-AI/modelrush-developer-tools/blob/main/SECURITY.md scope: ModelRush developer tools and, by its own wording, suspected vulnerabilities generally ("Do not open a public issue for a suspected vulnerability or include API keys, customer data, or authenticated request logs in a report.") reporting_guidance: Email a concise description, affected component, reproduction steps, and impact; remove secrets and personal data from all attachments. Ordinary bugs and documentation corrections go to the repository issue tracker. bug_bounty: false security_txt: false safe_harbor: not-stated evidence: - url: https://raw.githubusercontent.com/Moonveil-AI/modelrush-developer-tools/main/SECURITY.md status: 200 fetched: '2026-09-10'