Report privately
Include the affected version or commit, file or route, reproduction steps, impact, proposed mitigation when available, and whether public disclosure has occurred.
Keep out of public reports
Do not post credentials, exposed secrets, personal data, private prompts, customer data, full unreviewed logs, exploit details, or production authority.
Foundation response posture
Security reports receive priority, but the project does not promise a formal response SLA at foundation stage.
Safe research
Good-faith research should respect privacy, avoid disruption, remain within the public scope, and report findings privately. This statement is not a formal bug-bounty or legal safe-harbor agreement.
Public security reporting channels are not currently active. Do not publish exploit details or sensitive material in public.
