Please do not file a public GitHub issue for security vulnerabilities.
Email security@modudraft.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We aim to respond within 48 hours and will keep you updated on the fix timeline.
In scope: app.modudraft.com, api.modudraft.com, @modudraft/mcp npm package.
Out of scope: Third-party services (Cloudflare, Stripe, MongoDB Atlas).