← Documentation

Security

Source safety, credentials, and responsible disclosure.

{
  "version": "2026-08-v6",
  "source_policy": "Only public HTTPS sources are accepted; private and metadata-network destinations are blocked.",
  "credentials": "Never place API credentials in URLs or public logs.",
  "reporting": "POST /v1/support/security. Reports are rate-limited and auditable.",
  "disclosure": "Sensitive architecture, secrets, and exploit details are not returned by public Help endpoints."
}

Machine-readable response