Do not report security vulnerabilities in a public GitHub issue.
Use the private security-advisory form in this repository, or contact Motifuse through https://motifuse.com/contact and identify the report as an SDK security issue. Include the affected SDK version, impact, and a minimal reproduction using artificial data.
Never include Motifuse API keys, webhook secrets, npm tokens, customer documents, customer data, or private infrastructure URLs. Revoke any credential accidentally exposed before sending the report.
Security fixes are prioritized for the latest supported SDK release. Motifuse will coordinate disclosure and release notes with the reporter where practical.