Do not open a public GitHub issue. Email security@spliit.cloud with:
- description of the issue and impact
- steps to reproduce or proof-of-concept
- commit hash or version tested
- your contact info
Expect acknowledgement within 72 hours, triage within 7 days, regular status updates, and credit in release notes (unless you prefer anonymity).
In scope: authentication/session bypass, authorization bypass, XSS/CSRF, injection, unsafe document handling, leaked secrets, supply-chain issues in production dependencies.
Out of scope: misconfigured self-hosted instances, social engineering, third-party service issues (OpenAI, Cloudflare, SMTP providers — report to them).
90-day coordinated disclosure by default. Shorter or longer windows discussed case by case.