Report suspected vulnerabilities privately to security@atelier.diy. Do not
open public issues containing credentials, personal data, provider payloads, or
working exploit details.
Atelier uses public ATProto repositories deliberately for first-party records until Permissioned Spaces are available. This is not a confidentiality boundary. Credentials, external-provider content, encryption keys, and high-entropy feed tokens must remain in protected service storage.
Supported security work targets the current dev branch and the latest public
beta release. Production security fixes receive priority and a documented
coordinated-disclosure timeline.