Please report security issues privately rather than opening a public issue with vulnerability details.
Preferred channel: use GitHub's private vulnerability reporting / security advisory flow for this repository. If that flow is unavailable, open a public issue that only asks for a secure contact method; do not include exploit details, real customer data, API keys, private evaluation inputs, or proprietary evidence documents in the public issue.
Qiro Analyzer is local-first by default. External provider calls happen only when a non-mock provider is configured.