Please report suspected vulnerabilities through a private GitHub Security Advisory. Do not disclose the vulnerability in a public issue before it has been addressed.
This project does not offer a bug bounty. Reports are still appreciated and will be reviewed as promptly as possible.
The app handles Microsoft Entra tokens client-side and never sends tenant configuration data to third parties.