Use GitHub Security Advisories and private vulnerability reporting for this repository.
Do not post exploit details in public issues.
Include:
- steps to reproduce,
- impact,
- affected version or commit,
- suggested mitigation (if known).
This policy covers code and configuration in this repository.
The following must never be committed:
.envand any secrets,- keys, tokens, and certificates,
- runtime data, state, logs, scrolls, and vector databases,
- personal identifiers (emails, phone numbers, addresses, IBAN, and similar).
Trademark misuse is handled under TRADEMARK.md.