If you discover a security vulnerability, do not disclose it publicly first.
Please report via:
- Email: security@hiro.is
Include:
- affected component/path
- reproduction steps
- impact assessment
- suggested fix (if available)
- Initial acknowledgment: within 3 business days
- Triage and severity assessment: as soon as possible
- Coordinated disclosure after fix validation
This policy applies to the code in this repository and released package artifacts.