GitMoney OS takes security, data boundaries, and secret protection seriously.
If you discover a security vulnerability, credential leak, or data boundary issue within any GitMoney OS repository:
- Do not open a public issue or pull request detailing the vulnerability.
- Send a detailed report to the security contact at security@hitsuyoaku.io.
- Include the repository name, affected commit or path, steps to reproduce, and potential impact.
- Secrets, API tokens, passwords, private keys, and client-owned sensitive data are forbidden in public repositories.
- Private memory, internal strategy, and raw customer intel must remain inside private vault boundaries.
- Security claims must strictly reference point-in-time, dated API observations (for example, GitHub REST API audit timestamps). Generic security verifications or blanket pass verdicts are not permitted.