Read docs/enterprise/SECURITY.md for the threat model and actual implementation limits. This source release is not independently pentested or certified.
Before publishing a supported distribution, the operator must designate a real private vulnerability-reporting channel and response owner. No fabricated security email or service commitment is included. Do not post credentials or customer traces in public issues. Provide a sanitized reproduction, affected version, impact and relevant logs through the operator's approved private channel.