The canonical policy is SECURITY.adoc.
Report vulnerabilities privately through GitHub private vulnerability reporting (if enabled), or email j.d.a.jewell@open.ac.uk. Do not post secrets, private prompts, ledger contents, or exploit details in public issues.
This is development software. No stable-version support or backport schedule has been established. See the canonical policy for scope, safe research, response targets, and deployment precautions.