Report vulnerabilities privately through GitHub Security Advisories on theclaymethod/artifacture. Do not open a public issue for security reports.
Include what you found, how to reproduce it, and the affected version.
There is no bounty program. We ask for a 90-day disclosure courtesy window before any public write-up, so a fix can ship first.