Coders for Humanity
⌘ Shared context. Human contribution.
HANDBOOK / SECURITY

Responsible security reporting

Protect people and infrastructure while keeping development transparent.

Report privately

Do not publish vulnerabilities, personal data, credentials, or operational secrets in public issues. Once the official GitHub repository is configured, use its private vulnerability reporting feature. Until a private channel is published, contact an appointed maintainer privately; no public disclosure inbox is claimed by this preview.

What to include

Describe the affected version, reproduction steps, likely impact, and a safe proof of concept. Do not access other people’s data or test destructively. Agree a disclosure timeline with the maintainer.

Baseline controls

All exposed database tables use row-level security. Protected actions verify the current user on the server. Validate input, restrict external URLs, prevent cross-origin mutations, rate-limit submissions and claims, and audit privileged changes.