Report vulnerabilities privately to support@pipsync.io with subject [SECURITY]. Do not attach live MCP keys, access tokens, broker credentials, account IDs, customer prompts, or tool transcripts.
The public mock must remain offline and incapable of order execution.