Responsible Reporting

If you find a vulnerability affecting authentication, private replay access, public share links, exports, server execution, or stored run data, report it privately through the project maintainer before public disclosure.

In Scope

Out of Scope

Automated high-volume testing, social engineering, physical attacks, and testing against third-party services without authorization are out of scope.

Contact

Before production deployment, replace this section with a dedicated security email or SECURITY.md reporting process. For this project build, use the repository contact path.