Only the latest main branch is considered for security fixes. This repository does not provide a supported public deployment or availability commitment.
Use GitHub private vulnerability reporting through the repository's Security tab when available. Otherwise email contact@jadenrazo.dev with the affected path, impact, and a minimal reproduction.
Do not open a public issue containing credentials, tenant or customer data, message or attachment contents, integration secrets, database records, or a working exploit against a reachable service.
Authentication, tenant isolation, API and WebSocket authorization, chat and bot integrations, attachment handling, automation, AI-provider boundaries, database policies, and CI/release workflows are in scope. Dependency vulnerabilities should also be reported to the relevant upstream project.