Report vulnerabilities privately to support@pipsync.io with subject [SECURITY]. Do not attach live credentials, customer payloads, account identifiers, internal hostnames, or production latency traces.
The bundled server must remain loopback-only, synthetic-only, and simulator-only.