Do not report suspected vulnerabilities through public GitHub issues, discussions, or pull requests. Use the repository's private vulnerability reporting flow. If that flow is unavailable, email joschua.hass.sh@gmail.com.
Include the affected version and component, reproduction steps or a minimal proof of concept, the expected impact, and any proposed remediation. Do not include real workforce, employee, patient, or customer data.
Reports should receive an acknowledgement within three business days and an initial assessment within seven business days. These are response targets, not guarantees.
The hosted playground accepts structured scenario JSON only. It does not persist input, execute user-supplied code, or load third-party rule plugins. Public deployments must preserve the input, rate, worker, shift, demand-slot, and solver-time limits defined by the API adapter.
The supported versions, trust boundaries, abuse cases, controls, and residual risks are documented in the threat model. Security fixes are released for the latest alpha only until the project reaches beta.