Blue Pearmain is a personal tool designed for single-user, trusted local network use. The reviewer UI is not hardened for internet-facing or multi-user deployment — see the Scope and trust model section in the README.
There is no formal bug-bounty programme. If you find a security issue, please report it privately rather than opening a public GitHub issue:
Use GitHub's private vulnerability reporting for this repository. Please include a description of the issue, steps to reproduce, and any relevant environment details.