# Security Policy ## Reporting a Vulnerability Please do not report security vulnerabilities through public GitHub issues. Use one of these private channels instead: - GitHub private vulnerability reporting, if enabled for this repository - Email: jp@trailscoffee.com Include a short description, impact, affected version or commit, reproduction steps, and whether you believe funds, credentials, private keys, customer data, or production infrastructure are at risk. ## Scope Security-sensitive reports include authentication bypass, secret exposure, payment or wallet flaws, server-side request forgery, injection, cross-site scripting, dependency-chain compromise, authorization mistakes, and ways to access data outside the intended user or store boundary. ## Disclosure We aim to acknowledge credible reports within 72 hours. Please give us a reasonable remediation window before public disclosure, especially where customer data, credentials, Bitcoin/Lightning funds, or operational infrastructure could be affected. ## Contribution Hygiene Do not include real API keys, tokens, Nostr private keys, wallet seeds, macaroons, database dumps, customer data, or production logs in issues, pull requests, screenshots, or test fixtures.