generated: '2026-09-02' method: searched probe: true source: https://standardcompute.com/security program: published: true type: responsible disclosure (no bug bounty) bounty: false bounty_platform: null contact_email: contact@standardcompute.com submission_channel: email required_report_contents: - detailed description of the vulnerability - steps to reproduce - supporting evidence response_commitments: acknowledgement: within 2 business days initial_assessment: within 7 business days ongoing: keeps the reporter informed of remediation progress safe_harbor: offered: true text: >- "We will not take legal action against researchers who report vulnerabilities in good faith and do not access other users' data or disrupt the service." conditions: - good-faith reporting - no access to other users' data - no disruption of the service security_txt: served: false probed: - url: https://standardcompute.com/.well-known/security.txt status: 404 - url: https://api.stdcmpt.com/.well-known/security.txt status: 404 note: >- The policy exists and meets RFC 9116's substance — a contact, a policy page, stated response times and safe harbour — but the machine-readable file is not served. Publishing /.well-known/security.txt with Contact: mailto:contact@standardcompute.com and Policy: https://standardcompute.com/security would be a five-minute fix. published_security_practices: api_key_encryption: AES-256-GCM at rest, per-account derived key stored separately key_visibility: plaintext shown once at creation; only an encrypted blob plus last four characters retained key_recovery: none — provider states no administrative path to recover plaintext request_authentication: HMAC-SHA256 with constant-time comparison brute_force_control: failed authentication attempts rate limited transport: TLS 1.2+, Mozilla Intermediate profile, plaintext HTTP refused (not redirected) database_isolation: row-level security policies enforced in the database engine, tested by cross-account integration tests prompt_logging: >- None. Prompt and response content is not logged, stored or inspected on any plan, and the provider states there is no analytics or debugging mode that enables it. Only metadata — timestamp, model identifier, token count — is retained, for usage tracking and fair-use enforcement. upstream_isolation: >- Per-provider TLS with dedicated service credentials; credentials for one upstream cannot access another. The routing pool spans multiple providers and countries, so the jurisdiction handling a request can vary. training_on_customer_data: >- Standard Compute does not train its own models on customer prompts or outputs. It explicitly declines to warrant upstream providers' training policies and tells compliance-bound buyers to read the upstream provider's own terms. evidence: - source: https://standardcompute.com/security status: 200 fetched: '2026-09-02' kind: disclosure page keywords: - vulnerability - responsible disclosure - safe harbor