Security

Last updated: June 5, 2026

Responsible disclosure

If you believe you have found a security vulnerability in Vellio, email us at security@vellio.ai. We aim to respond within 72 hours and will work with you to understand and remediate valid reports.

Machine-readable contact details are also available at /.well-known/security.txt.

Scope

In scope for security reports:

  • The Vellio web application at vellio.ai and staging.vellio.ai
  • Hosted credits proxying and credit-ledger integrity
  • Marketplace publishing, ratings, and moderation flows
  • The Vellio browser extension (Chrome, Firefox, Edge)

Out of scope

  • Denial-of-service or volumetric load tests without prior written approval
  • Social engineering of Vellio staff or users
  • Physical attacks against facilities or hardware
  • Issues in third-party AI providers' own products (report those vendors directly)

Marketplace abuse

For copyright, illegal content, or other marketplace abuse that is not a technical vulnerability, contact abuse@vellio.ai. Vellio administrators review user reports in the admin report queue; severe or illegal content should be escalated to abuse@vellio.ai.

Acknowledgements

We thank the security researchers who help keep Vellio safe. This list will be updated as reports are resolved.

  • (No public acknowledgements yet.)

Related policies

See also our Privacy Policy, Sub-processors list, and Terms of Use.

← Back to home