VouchNet welcomes responsible reports of security issues affecting the repository or the hosted application. Please report vulnerabilities privately through GitHub Security Advisories, not through public issues, social posts, or support channels.
Include a concise description, affected route or component, reproduction steps, expected impact, and any mitigation you have identified. Do not include credentials, private user content, or other unnecessary personal data.
The project will acknowledge reports, investigate them privately, and coordinate an appropriate fix and disclosure process. The detailed engineering controls and threat assumptions are documented in docs/SECURITY.md and docs/THREAT_MODEL.md.