Security
Это содержимое пока не доступно на вашем языке.
Mildport is built by Capkrea GmbH in Germany. This page is the public vulnerability-disclosure policy and the monitored security contact. It is product policy, not legal advice.
Report a vulnerability
Section titled “Report a vulnerability”Write to [email protected]. English or German. Include the product surface (engine image, widget, or hosted cloud), a version or image digest, and a proof of concept that does not include customer data.
Please do not access other customers’ data, run volumetric denial-of-service, or demand payment as a condition of disclosure.
The same contact is advertised in security.txt (RFC 9116).
In scope. The Mildport engine and widget we ship, and the container images we publish.
Out of scope. Databases, object storage, and model endpoints you operate; issues that exist only in unmodified third-party software we depend on — report those upstream, and tell us if they affect a shipped image.
Verify a release
Section titled “Verify a release”Every published engine and sidecar image carries a software bill of materials (SPDX and CycloneDX). How to check a digest, including on a machine with no internet: Verify our images.
Other trust pages
Section titled “Other trust pages”- Data residency — where hosted data lives
- AI transparency — optional assist, human review
- Image access — private registry, per-customer grants