Legal

Security

What protects an account and a request on the way through, and the gaps that exist today.

The short version

There is no certification behind this page. What follows is a description of how credentials and requests are handled, most of which you can check yourself, followed by an explicit list of what the service does not have.

The prompt is not written to disk. It passes through the gateway in memory to reach the provider serving the model. The one exception is the agent endpoint, documented on the privacy page.

A request in flight

Traffic to freemodel.online is served over HTTPS, terminated at Cloudflare and carried to the origin over TLS. The gateway holds your prompt in memory while the upstream request is open, and does not write it to a database. Which third party receives it depends on the model you called, and the sub-processors page describes them by category rather than as a frozen list, because the set changes as supply changes.

HTTP Strict Transport Security is not currently sent by this site. The absence is deliberate to state here rather than leave for you to discover: without that header, a browser is willing to attempt a plain HTTP request to this domain. Whether the redirect catches it depends on the network in between.

Accounts and credentials

WhatHow it is stored or handled
Account passwordHashed with bcrypt, cost factor 10. Older accounts created before this were hashed differently; the password is rehashed on the next successful sign-in.
One-time sign-in codeOnly a SHA-256 hash of the code reaches the database, so a copy of the database cannot be turned into a live session.
Sign-in formBehind a bot challenge. A password alone does not complete a sign-in from an unrecognised client.
API keyBound to one account. Deletion calls are scoped to the key that authenticates them, so a key can only reach its own records.
Card dataNot held, because there is no payment flow to hold it: no card processor is integrated.

What the service does not have

A security page that lists only strengths is not worth reading. This is the other column.

ItemStatus
Third-party security certification (SOC 2, ISO 27001, or similar)No
Commissioned penetration test reportNo
Bug bounty programmeNo
HTTP Strict Transport Security headerNo
Published incident-response time commitmentNo
Prompts and replies written to a databaseNo, with one named exception on the privacy page

The first three are the ones a procurement review will ask for. The honest answer today is that this is a small service without a compliance programme, and a buyer who needs those documents should treat their absence as the deciding fact, not as a gap that a conversation will close.

Checking what can be checked

Two of the statements above you can verify in one request each, without an account.

  1. Step 1: Ask for the response headers of any page and look for the transport policy header. It will not appear, which is the point being made above: curl -sI https://freemodel.online/legal/security/
  2. Step 2: Call a route whose tier you are not entitled to without a key. The reply is a 401 for the missing key, and a key without the entitlement receives 402 — a refusal, never a silent charge: curl -s https://freemodel.online/v1/models needs no key at all, and is the same endpoint the model counts on this site come from.

Reporting a vulnerability

Write to privacy@freemodel.online with enough detail to reproduce the issue. There is no bounty, no acknowledgement deadline, and no legal safe-harbour document to sign — say what you found and it will be read and answered. Please do not test against other people's accounts or keys.

Security FAQ

Can FreeModel read my prompts?
Not from storage, because they are not written to a database — there is nothing to read after the request finishes. The request itself is forwarded to the provider serving the model. The single exception, the agent endpoint, is described in full on the privacy page.
Why publish a list of what you do not have?
Because the alternative is a buyer discovering it during procurement, after spending days on an evaluation. The absences are listed at the same level of detail as the strengths, and the list moves as things change.
Is the absence of HSTS a known gap?
Yes, and it is named here rather than implied. It is stated on this page because a reader checking response headers will find it in seconds, and finding it unmentioned would say more about the page than about the service.
What happens to my request while it is open?
It is held in the gateway's memory for as long as the upstream call is open, then released. Metadata — model, token counts, status, latency — is what persists, as described on the privacy page.
Do you sell or share anything recorded?
No. Metadata exists for routing, quota accounting and failure diagnosis, and is not used for advertising or sold. The sub-processors page names every party that receives anything.

FreeModel is a product of Aiglade. Last updated 2026-09-30.