Security, privacy, and human control are product behavior at Getyak.
Unless a repository states otherwise, security fixes target the default branch. Public specifications and early foundations may not be production-ready; read each repository's status notice before using it with real data.
Do not disclose vulnerability details in a public issue, discussion, pull request, commit, or screenshot.
Use the repository's Security tab and private vulnerability reporting when it is available. Include:
- the affected repository and revision;
- impact and realistic preconditions;
- minimal reproduction steps;
- any known mitigation;
- whether sensitive or personal data may have been exposed.
If private vulnerability reporting is not available, open a minimal public issue asking a maintainer to establish a private reporting channel. Do not include exploit details, secrets, personal data, or a working proof of concept in that issue.
We will acknowledge a complete report, assess scope, coordinate a fix, and publish details only after affected users have a reasonable mitigation path.
Please avoid:
- accessing or modifying data that is not yours;
- degrading service availability;
- social engineering or credential attacks;
- retaining sensitive data beyond what is required to report the issue;
- testing against real candidate, customer, journal, or conversation data without explicit authorization.