Skip to content

Security: DavidTimar1/ModelsDB

SECURITY.md

Security Policy

ModelsDB runs entirely on your own machine. It serves a web UI on localhost, keeps its data in a local SQLite file, and reaches the network only to fetch the public model catalog (OpenRouter, and optionally GitHub for the catalog and update check). There are no accounts, no server, and no telemetry.

Reporting a problem

Found a security issue, or something that just looks off? Please tell me.

You can reach me through any of the channels listed on my GitHub profile: https://github.com/DavidTimar1. If the issue is sensitive, please use a private channel rather than posting it in the open.

This is a hobby project, so I can't promise a fixed turnaround. I do read every report and take real issues seriously.

Supported versions

Fixes go into the latest release. Please check against the newest binary before reporting.

There aren't any published security advisories