This is proprietary software (see LICENSE). Please handle security
issues responsibly and privately.
- Do not open a public issue for security problems.
- Use GitHub's private vulnerability reporting (repository Security tab → Report a vulnerability), or contact the maintainers directly.
- Include steps to reproduce, the affected component, and the potential impact.
Please allow a reasonable time for a fix before any disclosure.
- Never commit
.env, connection strings, JWT signing keys, API keys, or.pfx/.p12private keys. These are ignored via.gitignore. - Runtime secrets are supplied through environment variables — see
.env.example. - If a credential is ever exposed in a commit, rotate it immediately and scrub it from history before it is shared further.