Security fixes are applied to the current main branch and the public deployment.
Please use GitHub's private vulnerability reporting feature under Security → Advisories → Report a vulnerability. Do not open a public issue for an exploitable weakness or include credentials, private data, or production secrets in a report.
For calculation defects that do not create a security impact, use the calculation bug issue form instead.
Useful reports include input-validation bypasses, denial-of-service conditions, unsafe response headers, container or dependency risks, and unintended data exposure. The application does not require accounts and should not collect personal information.