cueq is a source-only alpha evaluation workspace. Do not use it with real employment, payroll, health, or other personal data.
There is no production-supported version or security-maintenance commitment. Reports should identify the exact commit or tag they concern.
Do not open a public issue for a suspected vulnerability. Use the repository's private vulnerability report. If GitHub does not expose that form, do not disclose the report in a public issue. Include a minimal reproduction, the affected source path or commit, impact, and any safe mitigation you identified.
Do not include credentials, tokens, real personal data, or production logs in the report.
The detailed security, authorization, and privacy design is in docs/SECURITY.md. This policy does not promise response times, supported versions, or production security certification.