Report security concerns privately to the project maintainers rather than opening a public issue. Include the affected surface, reproduction steps, and likely impact. Do not include real player credentials or private match data.
FrontIQ stores secrets only in approved server environments. Extension device credentials must be revocable, rotatable, and scoped. Logs must not contain tokens, raw sessions, or private capture payloads.
Supported releases will be listed when the first public build is available.