Please report suspected vulnerabilities privately to contact@elyzesolutions.ch. Do not open a public issue for a vulnerability or include credentials, tokens, customer data, or exploit details in public.
Release binaries are built from the private Helvstack source repository and published with SHA-256 checksums. The npm and PyPI launchers verify the selected binary before executing it.