Responsible Reporting
If you find a vulnerability affecting authentication, private replay access, public share links, exports, server execution, or stored run data, report it privately through the project maintainer before public disclosure.
In Scope
- Unauthorized access to private runs or exports.
- Authentication or ownership bypasses.
- Public share token leakage or escalation.
- Server-side injection, denial of service, or unsafe file access.
Out of Scope
Automated high-volume testing, social engineering, physical attacks, and testing against third-party services without authorization are out of scope.
Contact
Before production deployment, replace this section with a dedicated security email or SECURITY.md reporting process. For this project build, use the repository contact path.