Report suspected vulnerabilities privately through GitHub Security Advisories. Do not include real tenant IDs, tokens, document content, group membership, or search results in an issue. Maintainers target acknowledgment within three business days and will coordinate remediation and disclosure.
Only the latest release line is supported. Treat Graph permissions, index write access, cache invalidation, application authentication, and the post-search authorization check as security boundaries requiring review.