Simpler Redact's entire claim is that nothing leaves your machine. If you find a way that
claim breaks — any outbound network call beyond localhost, any path where unredacted
content or the entities key can escape, any way a crafted document defeats verification —
report it privately first, through GitHub private vulnerability reporting
(the Security tab → Report a vulnerability). If you would rather use email,
support@simpler.asia reaches the maintainer — but GitHub's private report is preferred for
anything unpatched, because it keeps the disclosure and the fix in one place.
Please do not open a public issue for an unpatched leak. You'll get an acknowledgment, a fix or a published advisory, and credit if you want it. There is no bounty program; this is a free tool.
Redaction misses (a span the engine should have caught but didn't) are not security vulnerabilities — they are benchmark findings. Open a public issue with a minimal reproducing document; misses with a failing bench case are the most valuable issues this project can receive.