Security
Last updated: June 5, 2026
Responsible disclosure
If you believe you have found a security vulnerability in Vellio, email us at security@vellio.ai. We aim to respond within 72 hours and will work with you to understand and remediate valid reports.
Machine-readable contact details are also available at /.well-known/security.txt.
Scope
In scope for security reports:
- The Vellio web application at vellio.ai and staging.vellio.ai
- Hosted credits proxying and credit-ledger integrity
- Marketplace publishing, ratings, and moderation flows
- The Vellio browser extension (Chrome, Firefox, Edge)
Out of scope
- Denial-of-service or volumetric load tests without prior written approval
- Social engineering of Vellio staff or users
- Physical attacks against facilities or hardware
- Issues in third-party AI providers' own products (report those vendors directly)
Marketplace abuse
For copyright, illegal content, or other marketplace abuse that is not a technical vulnerability, contact abuse@vellio.ai. Vellio administrators review user reports in the admin report queue; severe or illegal content should be escalated to abuse@vellio.ai.
Acknowledgements
We thank the security researchers who help keep Vellio safe. This list will be updated as reports are resolved.
- (No public acknowledgements yet.)
Related policies
See also our Privacy Policy, Sub-processors list, and Terms of Use.