Do not open a public issue for a vulnerability that could expose private memory, bypass approval gates, or execute unintended commands. Report it privately through GitHub Security Advisories once the repository is published.
EvoPilot data is local but may contain personal preferences and project context. Backups should be protected like other private work data. Never include EvoPilot databases in bug reports.
The policy tool is advisory defense in depth. Codex sandboxing, approvals, operating-system permissions, and service-side authorization remain the enforcement boundaries.