No released or supported version exists yet. Security review currently applies
to the planning documents and future pre-release code on main.
Please report vulnerabilities privately through GitHub's Report a vulnerability / private security advisory flow for this repository. Do not open a public issue containing exploit details, keys, credentials, private identifiers, or user data.
Include, when safe:
- affected commit or release;
- impact and prerequisites;
- minimal synthetic reproduction;
- whether confidentiality, integrity, authorization, replay protection, availability, backup, or recovery is affected;
- suggested mitigation, if known.
Do not test against systems or data you do not own or have permission to use.
Security claims are valid only after the corresponding implementation, verification, and release gate exists. Draft protocol and threat-model documents are design intent, not proof of confidentiality or production readiness.