Report vulnerabilities to security@tokenpolice.ai. Do not open a public issue for security reports.
We acknowledge reports within 3 business days and aim to ship a fix within 90 days of confirmation. Please include the package name and version, a description of the issue, and steps to reproduce.
The SDK runs inside your process and sends only token counts and the session metadata you attach to TokenPolice — never prompt or completion text. See https://tokenpolice.ai/privacy.