Please report vulnerabilities privately to [email protected] — not via public issues. Include reproduction steps and the commit or version affected. We'll acknowledge within 48 hours.
Supported: the latest release of the gateway and SDKs.
Out of scope: issues requiring a compromised provider account, and denial-of-service against your own self-hosted instance.