| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
If you discover a security vulnerability within ModelForce, please send an email to security@modelforce.dev. All vulnerabilities will be promptly addressed.
Please do not report security vulnerabilities through public GitHub issues.
ModelForce downloads provider binaries (Piper, etc.) from external sources. These binaries are:
- Downloaded over HTTPS
- Stored in user-local directories (
~/.modelforce/) - Executed with user permissions
Recommendation: Only install providers from trusted sources.
Voice files are downloaded from HuggingFace and stored locally. No data is sent to external services during synthesis.
- Provider downloads: One-time fetch from GitHub/HuggingFace
- XTTS server: Optional HTTP connection to local/remote server
- No telemetry or analytics
- Keep ModelForce updated
- Use trusted provider sources
- Review provider binaries before installation
- Use local XTTS server when possible
For security concerns, contact: security@modelforce.dev