Please report suspected vulnerabilities privately to:
security@hippocortex.dev
Include:
- Affected versions/commit
- Reproduction steps
- Potential impact
- Suggested mitigation (if known)
- We acknowledge reports within 3 business days.
- We validate and triage severity.
- We prepare a fix and release notes.
- We disclose once users have a reasonable patch window.
Please do not open public issues for unpatched vulnerabilities.