Report privately

Include the affected version or commit, file or route, reproduction steps, impact, proposed mitigation when available, and whether public disclosure has occurred.

Keep out of public reports

Do not post credentials, exposed secrets, personal data, private prompts, customer data, full unreviewed logs, exploit details, or production authority.

Foundation response posture

Security reports receive priority, but the project does not promise a formal response SLA at foundation stage.

Safe research

Good-faith research should respect privacy, avoid disruption, remain within the public scope, and report findings privately. This statement is not a formal bug-bounty or legal safe-harbor agreement.

Public security reporting channels are not currently active. Do not publish exploit details or sensitive material in public.