CorpOS is a company-day simulation and reference architecture — not a production-hardened SaaS. See the root SECURITY.md for posture, guarantees, and supply-chain notes.
If you believe you have found a security vulnerability in CorpOS:
- Do not open a public GitHub issue.
- Report privately via GitHub Security Advisories (preferred).
- If that link returns 404, ask a repo admin to enable Settings → Code security → Privately report a security vulnerability, then retry.
- Include reproduction steps and impact. Do not include secrets or live credentials.
- We aim to acknowledge within 72 hours and coordinate a fix under a 90-day responsible disclosure window.
Conduct issues belong under CODE_OF_CONDUCT.md, not security advisories.