Report vulnerabilities privately by email to hello@septagon.dev. Do not open
a public issue with vulnerability details.
Include the affected repository and tag or commit, the impact, reproduction steps and any proposed mitigation. Remove credentials and client data from the report. We aim to acknowledge reports within 48 hours and coordinate a fix with the reporter.
This is the default reporting policy for repositories in septagon-oss,
including PlatformKit and PlatformKit Mobile. A repository's own security
policy takes precedence and defines any version-specific support commitments.
Consult that policy and the product's release notes for fixes and upgrade
instructions. This organization default does not promise maintenance for every
historical version or archived repository.