Security fixes are provided for the latest published major version of the usertold npm package.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository, or email security@usertold.ai with the affected version, reproduction steps, and impact.
We will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.
Never include access tokens, participant data, interview media, transcripts, or other customer data in a report. Use synthetic examples and revoke any credential that may have been exposed.