Do not report security or privacy vulnerabilities in a public issue when disclosure could expose participant data, consent records, implementation logs, or deployment details.
Use the repository’s Security → Report a vulnerability path for confidential vulnerability reports. If that feature is unavailable, email team@playa-ai.org with the subject “EELP security report.” Do not include participant narratives in the initial report.
The Foundation will acknowledge a report within 5 business days, provide an initial assessment within 10 business days, and coordinate disclosure based on participant risk and remediation readiness.
Never commit:
- participant narratives or identifiers;
- raw consent or onboarding logs;
- deletion-request records;
- private contact lists or outreach notes;
- API keys, tokens, credentials, or environment files;
- unredacted source-workspace exports.