UK enterprise · NCSC-aligned
Security posture
Updated 19 September 2026. England & Wales. Parent HQ only.
Scope
Modex Ventures (“Modex”, “we”, “us”) is the parent laboratory and holding studio operated from the United Kingdom. The parent site is modexventures.com. Operating companies close on their own subdomains. This parent is not a product SKU.
This notice describes the parent HQ. Operating companies publish their own security pages. We do not claim ISO 27001 or Cyber Essentials on this parent until a certificate exists — we will not invent one.
Controls we actually run
TLS on the public edge. Least-privilege operator access to hosting and payment dashboards. Membership checkout refused at the API (HTTP 403) so Scout / Operator / Partner cannot be purchased. Secrets are operator-provided environment variables — never committed.
Vault cards withhold product names on the public mystery rail. Sealed drawers MX-321–329 show capability only. Research deposits, when Stripe is configured, use hosted Checkout; when unset, the rail records a stub and says so.
Data classes on this parent
This site is not a clinical system, not an AML dossier store, not a pupil MIS, and not a housing evidence vault. Do not upload those classes here. Engines that handle them (Clara Desk, Citadel AML, Continuum, AwaabFlow) close on their own domains with their own DPAs.
Vulnerability disclosure
Report a vulnerability on the parent via the Access Terminal introduce form, marked “Security”. Do not publicly disclose until we have had a reasonable window to remediate. We do not run a paid bug bounty on this parent today.
Subprocessors
Hosting / edge: the operator’s chosen UK/EU-capable provider. Payments: Stripe (research signals only, when configured). Auth magic links and webhooks exist as routes; they do not mint a public membership.