Report security issues privately to hello@easycris.com.
Please include:
- Affected component and version/commit.
- Reproduction steps or proof of concept.
- Impact assessment.
- Any suggested mitigation.
- Initial triage acknowledgment target: 3 business days.
- Follow-up status updates are provided during investigation.
- Coordinated disclosure is preferred after a fix is available.
Do not open public issues for unpatched security vulnerabilities.