SECURITY

Protect the system. Minimize the data.

Last reviewed September 2, 2026

Our approach

The public Blackfrost website is designed around data minimization and a small third-party surface. Its production build includes dependency auditing and avoids advertising trackers and analytics scripts. Controls for client work, model delivery, and private infrastructure are defined separately for each engagement and should not be inferred from this public-site statement.

Payments and model delivery

Blackfrost creates itemized checkout sessions on the server from an allowlisted model catalog; browser-supplied prices and product identifiers are never trusted. Payment is completed on Stripe, and Blackfrost does not receive or store full card numbers. A signature-verified Stripe webhook validates the immutable cart and every paid line item, checks the collected billing country before delivery, and uses a retry-safe per-item ledger to grant the Hugging Face username entered at checkout access to each purchased gated repository. The return page reads only server-recorded fulfillment status; the browser query never triggers delivery. Event and order records are not writable from the public browser.

Report a vulnerability

Email support@blackfrostai.com with only the affected Blackfrost URL and a high-level request for a secure reporting channel. Do not post the issue publicly or send exploit code, credentials, personal data, or customer information in the initial message.

Responsible research rules

  • Do not access, modify, destroy, or retain data that is not yours.
  • Do not degrade service, automate high-volume testing, or target third-party providers.
  • Stop testing and report immediately if you encounter personal or confidential data.
  • Allow reasonable time for investigation and remediation before disclosure.
  • Testing of model weights and third-party repositories is governed by their separate terms and authorization boundaries.