Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability
reporting for this repository. If private reporting is unavailable, contact a verified
PeerbitsSolution organization maintainer privately.
The project intends to acknowledge valid reports within three business days.
Until 1.0.0, only the latest 0.x release receives security fixes. This policy will be reviewed for the first stable release.
This library does not send data over a network and must never contain PHI, production credentials, or client-identifying content. Consuming applications remain responsible for access control, encryption, audit logging, retention, consent, and applicable healthcare privacy obligations.