Security reports are currently accepted for the latest repository release and its companion HTML demonstrations. The white papers and demonstrations are reference materials, not production services.
Please do not disclose a potentially sensitive vulnerability in a public Issue or Discussion.
Use the repository's Report a vulnerability function under the Security tab to submit the report privately. Include:
- the affected file and version;
- a concise description of the issue and its possible impact;
- reproduction steps or a minimal proof of concept;
- any suggested mitigation, if available.
The project will acknowledge a complete report when practical and will coordinate disclosure if a correction is required. This policy does not create a bug-bounty program or promise compensation.
The included HTML demonstrations are designed for local, offline inspection with synthetic data. They do not connect to banks, enterprise systems, or external services and should not be used as production controls.