Public disclosure status
Unpublished inboxNo monitored public security address is configured in this build, so this page does not claim an active intake channel.
Security disclosure · Not launch-ready
Security pages are useful only when they tell the truth. This one does: the product has significant hardening work already, but the public disclosure operation is not staffed or launched from this branch.
Public disclosure status
Unpublished inboxNo monitored public security address is configured in this build, so this page does not claim an active intake channel.
True blockers
Operations still requiredMFA, least privilege, secret rotation, monitored reporting, incident playbooks, and zero open critical/high findings remain required before launch claims.
The customer platform plan also requires cross-account review, CSRF/XSS/CSP abuse testing, release-revocation drills, and an independent security review before the security program can be described as ready.
This placeholder proves the site does not fake a disclosure intake. A monitored security mailbox, triage process, and acknowledgement workflow are still operator work items.