Please report security issues privately via email:
smith@antiparty.co
Include:
- affected version and commit (if known)
- reproduction steps
- expected impact
- any proof-of-concept details
Do not open public issues for active vulnerabilities.
- This repository is source-available reference software under BUSL-1.1.
- Demo configs and examples are not production credit models.
- No production PII is required for this project's demo paths.
- Do not use real customer, borrower, or regulated production data in examples or tests.
Local package defaults do not include enterprise auth, network hardening, or managed secret storage. Those controls must be applied in deployment architecture.