This is an experimental hobby project for microcontroller hardware — it is not intended for production or security-sensitive use, and there are no guarantees.
If you find something that looks security-relevant, please report it privately to marcel.duetscher@gmail.com rather than opening a public issue. I'll take a look when I can, but response times are best-effort.