No enumeration
Anonymous pull requests get a flat 401 with no model list, no count and no timing difference between a real and a fictional identifier.
The mirror is static, the client is a signed release artifact and the transfer endpoint is key-gated. That does not make it interesting to attack, but it does make it worth stating the rules: report privately, get a fix before a story, and do not test other people's keys.
Use the security contact listed in /.well-known/security.txt. Include the affected component, the release line, a minimal reproduction and the impact you believe it has. A proof of concept is welcome; a working exploit against a live key is not.
Contact: mailto:security@modelfoundry.invalid
Preferred-Languages: en, ru
Encryption: signed message with the project key
Canonical: /.well-known/security.txt
Policy: https://modelfoundry.invalid/security
Some of these are unusual, so it is worth writing down why.
Anonymous pull requests get a flat 401 with no model list, no count and no timing difference between a real and a fictional identifier.
Every build carries a signature. A mirror that rewrites a manifest is rejected by the client rather than silently trusted.
No fonts, no analytics, no CDN scripts. A static mirror that calls out to someone else is a mirror with an extra dependency.
Request metadata only, kept for abuse control, with no request bodies, no credentials and no prompt content.
Rate limits live at the edge and expire on their own. Nothing about an anonymous reader is retained beyond the limit window.
Model files are parsed outside a sandbox, so we do not accept untrusted checkpoints from anonymous uploaders. Contributors build them themselves.