Legal
Security
What protects an account and a request on the way through, and the gaps that exist today.
The short version
There is no certification behind this page. What follows is a description of how credentials and requests are handled, most of which you can check yourself, followed by an explicit list of what the service does not have.
The prompt is not written to disk. It passes through the gateway in memory to reach the provider serving the model. The one exception is the agent endpoint, documented on the privacy page.
A request in flight
Traffic to freemodel.online is served over HTTPS, terminated at Cloudflare
and carried to the origin over TLS. The gateway holds your prompt in memory while the
upstream request is open, and does not write it to a database. Which third party receives
it depends on the model you called, and the
sub-processors page describes them by category
rather than as a frozen list, because the set changes as supply changes.
HTTP Strict Transport Security is not currently sent by this site. The absence is deliberate to state here rather than leave for you to discover: without that header, a browser is willing to attempt a plain HTTP request to this domain. Whether the redirect catches it depends on the network in between.
Accounts and credentials
| What | How it is stored or handled |
|---|---|
| Account password | Hashed with bcrypt, cost factor 10. Older accounts created before this were hashed differently; the password is rehashed on the next successful sign-in. |
| One-time sign-in code | Only a SHA-256 hash of the code reaches the database, so a copy of the database cannot be turned into a live session. |
| Sign-in form | Behind a bot challenge. A password alone does not complete a sign-in from an unrecognised client. |
| API key | Bound to one account. Deletion calls are scoped to the key that authenticates them, so a key can only reach its own records. |
| Card data | Not held, because there is no payment flow to hold it: no card processor is integrated. |
What the service does not have
A security page that lists only strengths is not worth reading. This is the other column.
| Item | Status |
|---|---|
| Third-party security certification (SOC 2, ISO 27001, or similar) | No |
| Commissioned penetration test report | No |
| Bug bounty programme | No |
| HTTP Strict Transport Security header | No |
| Published incident-response time commitment | No |
| Prompts and replies written to a database | No, with one named exception on the privacy page |
The first three are the ones a procurement review will ask for. The honest answer today is that this is a small service without a compliance programme, and a buyer who needs those documents should treat their absence as the deciding fact, not as a gap that a conversation will close.
Checking what can be checked
Two of the statements above you can verify in one request each, without an account.
- Step 1: Ask for the response headers of any page and look for the transport policy
header. It will not appear, which is the point being made above:
curl -sI https://freemodel.online/legal/security/ - Step 2: Call a route whose tier you are not entitled to without a key. The reply is a
401 for the missing key, and a key without the entitlement receives 402 — a refusal,
never a silent charge:
curl -s https://freemodel.online/v1/modelsneeds no key at all, and is the same endpoint the model counts on this site come from.
Reporting a vulnerability
Write to privacy@freemodel.online with enough detail to reproduce the issue. There is no bounty, no acknowledgement deadline, and no legal safe-harbour document to sign — say what you found and it will be read and answered. Please do not test against other people's accounts or keys.
Security FAQ
Can FreeModel read my prompts?
Why publish a list of what you do not have?
Is the absence of HSTS a known gap?
What happens to my request while it is open?
Do you sell or share anything recorded?
FreeModel is a product of Aiglade. Last updated 2026-09-30.