Please report suspected vulnerabilities privately to contact.surl.tw@gmail.com with the subject “Humanread security report”. Include affected component/version, impact, and safe reproduction details.
Do not include a Humanread API key, OAuth secret, private key, personal data, private manuscript, or operational exploit against the production service. Do not test against accounts or works you do not control.