This repository accepts security reports for:
- Python package runtime and public API (
zpe_mental/). - Rust-native extension and the Python/Rust boundary (
src/lib.rs,Cargo.toml,pyproject.toml). - Packaging, install, and release configuration committed in this repository.
Please report vulnerabilities privately to architects@zer0pa.ai with:
- A clear impact summary.
- Reproduction steps or proof-of-concept.
- Affected versions or commit ranges.
- Suggested remediation when available.
If you need a private handoff channel beyond email, request it in the initial report. Do not post secrets, private keys, or live exploit payloads in a public issue.
- Initial acknowledgement: within 5 business days.
- Triage and severity classification: within 10 business days.
- Remediation timeline: shared after triage.
Public disclosure should be coordinated after a fix is available.