prosaic handles litigation files — treat every report accordingly.
Do not open public issues for security problems. Anything touching credential handling, the redaction pipeline, sealed-content handling, or the AI triage layer's prompt-injection surface should be reported privately to the maintainer (contact in the repository metadata). Include reproduction steps against FICTIONAL data only — never include real case material in a report.
Background on the security model: docs/security.md.