Report security issues privately to the maintainers via GitHub Security Advisories on PaperPit/kar-dots, or open a private discussion if advisories are unavailable.
Do not file public issues with exploit details or leaked credentials.
Security fixes target the latest main / newest release tag. Self-hosted operators should pull regularly.
See docs/SECURITY.md for CSP / rate limits, BYOK keys, what self-hosting does not cover, and key rotation.
Full threat model and self-host hardening notes: docs/SECURITY.md.