The runtime is not implemented yet. Security/privacy requirements are defined in the design.
For an exploitable issue, use this repository's GitHub Report a vulnerability interface if available. If private reporting is unavailable, open a minimal issue asking for a private contact channel; do not include exploit details, keys, private feed images, account information, or personal logs in a public issue.
For ordinary design feedback, use an issue and reference the affected contract or requirement. Security controls, approval boundaries, cloud-routing consent, and retention semantics require review before release.
Only the latest released version will initially receive security fixes. There are no runtime releases to support today. A concrete response/patch policy will be adopted before the first public binary release.