security
Security is part of how we build.
We don’t promise perfect safety | no honest software company can.
What we commit to is a consistent, reviewable way of working.
Practice
What that means in practice
We don’t publish internal infrastructure details or secret-management specifics. What we describe here is our approach | not a security guarantee.
Least privilege
Components, services, and people receive only the access they need | nothing broader by default.
Secure defaults
Products ship with safe settings enabled, so protection doesn’t depend on expert configuration.
Server-side validation
Anything coming from the client is treated as untrusted and verified on the server.
Repeated & verified review
Security is revisited as features change, and changes are observed in real operating environments.
Scope
These principles apply across Modelyn products, including Modelyn Mail. Product-specific security details, where relevant, are documented with the product itself.
Reporting
If you believe you’ve found a security issue in a Modelyn product, please reach out via our contact page with a clear description and steps to reproduce. We review every report.