Modal logo

Security and privacy at Modal

This page outlines Modal’s security and privacy commitments.

Our Trust Center provides compliance documentation, including our SOC 2 Type II report, our list of subprocessors, and details of our security controls.

Information security program 

Our information security (InfoSec) program covers three practice areas: application security, corporate security, and network and infrastructure security.

Application security (AppSec)

AppSec covers how we build, test, review, and deploy the Modal platform.

  • We build our software using memory-safe programming languages, including Rust (for our worker runtime and storage infrastructure) and Python (for our API servers and Modal client).
  • Software dependencies are automatically audited for known vulnerabilities.
  • We make decisions that minimize our attack surface. Most interactions with Modal are well-described in a gRPC API, and occur through modal, our open-source command-line tool and Python client library.
  • We have automated synthetic monitoring test applications that continuously check for network and application isolation within our runtime.
  • We force HTTPS (TLS) for all services, including our public website and the Dashboard. Our client library connects to Modal’s servers over TLS and verifies TLS certificates on each connection.
  • Your data is encrypted in transit and at rest.
  • All public Modal APIs use TLS 1.3.
  • Internal code reviews are performed using a PR-based development workflow, and we engage external penetration testing firms to assess our software security.
Corporate security (CorpSec)

CorpSec covers how our employees access internal systems.

  • Access to internal systems requires single sign-on (SSO) through our identity provider.
  • Phishing-resistant multi-factor authentication (MFA) is required for all employee accounts.
  • We regularly audit access to internal systems.
  • Employee laptops are enrolled in mobile device management (MDM) with full disk encryption enforced.
Network and infrastructure security (InfraSec)

InfraSec covers how we secure the infrastructure that runs your workloads.

  • We continuously monitor platform logs and metrics through third-party observability providers.
  • Each container runs in its own sandbox, isolated from the host, using primitives like gVisor or microVMs.
  • We run business continuity and security incident exercises every year.

Vulnerability remediation 

We remediate vulnerabilities in Modal’s systems within the timeframes below, measured from when a fix becomes available. Severity is based on the CVSS rating of the vulnerability and our assessment of its impact on Modal.

Severity timeframes 

  • Critical: 24 hours
  • High: 1 week
  • Medium: 1 month
  • Low: 3 months
  • Informational: 3 months or longer

Bug bounty program 

We welcome responsible disclosure from the security community and run a private bug bounty program through HackerOne. To participate, email security@modal.com with your HackerOne username and we will send an invite. When performing security research, you must use a Modal Workspace whose name ends in -H1-<username>, where <username> is your HackerOne username.

Data privacy 

This section covers how long each type of data is kept, which products retain no data at all, and where your data is stored.

Data retention 

Retention varies by product; the table below shows how long each type of data is retained. All stored data is encrypted at rest.

DataProductRetention
Inputs and outputsFunctions (.remote, .spawn, .map, Web Functions, Scheduled Functions)Up to 7 days, then deleted
Request and response payloadsServer and Auto EndpointsNot stored — proxied directly to your container
App and container logsFunctions, SandboxesPlan-dependent: 1 day on Starter, 30 days on Team, configurable on Enterprise (see pricing)
Audit logsWorkspace (Enterprise)Per Enterprise contract (see Audit logs)
FilesVolumes, ImagesPersistent until you delete them
Memory snapshotsFunction memory snapshots, Sandbox memory snapshots7 days after creation
Filesystem snapshotsSandbox filesystem snapshots30 days after creation (configurable; stored as Images)
Directory snapshotsSandbox directory snapshots30 days after creation (configurable)
EntriesDicts7 days after last read or write
PartitionsQueuesConfigurable per-partition TTL (default 24 hours)
App, Function, and container metadataAll productsStored for the lifetime of your account

Zero data retention 

Dedicated and Shared inference endpoints have zero data retention. Request and response payloads are never written to disk and pass through Modal only as in-flight network traffic.

Data residency 

See our data residency guide for where each type of data is stored and the controls available for residency requirements.

Shared responsibility model 

Modal prioritizes the integrity, security, and availability of customer data. Under our shared responsibility model, you also have responsibilities in the areas below.

AreaModalCustomer
Access and secretsProvides access controls, including SSO, SCIM, API tokens, and RBAC, and Secrets management for storing credentials.Manage the identities in your Workspace, assign roles, and rotate and remove API tokens. Own the contents and rotation of your Secrets.
Encryption and network securityEncrypts data in transit with TLS 1.3 and at rest.Decide which endpoints you expose and how they are authenticated. Apply any additional encryption your data requires, such as encrypting sensitive fields before they reach Modal.
VulnerabilitiesPatches the platform and runtimes within our severity timeframes and audits our dependencies for known vulnerabilities.Patch your Images, dependencies, and code.
Untrusted codeProvides isolation primitives for running untrusted code through Restricted Functions and Sandboxes.Run untrusted code, such as LLM-generated or end-user-submitted code, using those primitives and with guardrails such as egress restrictions, resource limits, and timeouts. Keep Secrets and credentials out of untrusted workloads.
Data lifecycleEnsures the durability of managed storage and applies our retention and deletion policies.Maintain backups of the data you store in Modal and routinely verify their integrity.
OperationsOperates the platform for high availability, monitors it, and responds to platform incidents.Monitor your applications and design for failover.
ComplianceMakes our audit reports and control documentation available on our Trust Center.Determine which laws and regulations apply to your organization and your data, and configure and use Modal to meet them.

Security features 

We provide security features across our products to help you secure your workloads, such as single sign-on, Role-Based Access Control (RBAC), Sandbox network access controls, audit logs, and customer-supplied encryption keys.

Compliance standards 

System and Organization Controls (SOC) 2 Type II 

For our latest SOC 2 Type II audit report, please visit our Trust Center to request access.

General Data Protection Regulation (GDPR) 

A Data Processing Addendum (DPA) is available on our Trust Center.

Health Insurance Portability and Accountability Act (HIPAA) 

The following products are out of scope and should not be used for protected health information (PHI):

Out of scope for PHINotes
Volumes v1Use Volumes v2 instead
ImagesExcluding Filesystem and Directory Snapshots
Memory Snapshots—
User code—

Contact 

security@modal.com