Do not open a public issue for a suspected security or privacy vulnerability.
Until a dedicated security contact is configured, report it privately to the project owner and include:
- A clear description of the issue.
- Steps to reproduce it.
- Potential impact, especially on location, contact, authentication, or tracking-link data.
- Any suggested mitigation.
KAAVAL handles emergency contacts and location data. Do not commit, log, attach to issues, or place in test fixtures any real phone numbers, precise locations, tracking tokens, credentials, or production data.
Only the current development branch and the latest approved release candidate will receive security fixes.