Report suspected vulnerabilities privately to security@pisama.ai. Include the affected version, a minimal reproducer, and the impact you observed.
We will acknowledge reports within two business days. We aim to provide a fix or mitigation within seven business days for confirmed high-severity issues.
Only the latest minor release is supported. We credit reporters in release notes unless they prefer to remain anonymous.