Security and Responsible Disclosure

Security controls, reporting and incident handling expectations.

Last updated / Cập nhật: 2026-09-07

Controls

Use least privilege, strong passwords, MFA, scoped API tokens, HTTPS, protected backups, independent audit logs and restricted deployment targets. Operators must configure secrets outside prompts and avoid exposing the management port directly to the Internet.

Report a vulnerability

Send a minimal report through Contact. Include affected route/component, impact, reproduction steps and a safe contact channel. Do not access other users' data, persist access or perform destructive testing.

Incident response

We investigate, contain, preserve evidence, remediate and communicate material incidents as required by the applicable agreement and law. Customers operating self-hosted instances remain responsible for their own incident response and notifications.