Please do not report vulnerabilities in public issues.
Send security reports to support@rel.me with a concise description, reproduction steps, affected versions, and impact. Avoid including credentials, private browsing data, or other sensitive user data unless we coordinate a secure transfer method first.
The local API is bound to loopback and is intended for trusted software running as the same macOS user. REL.app remains the only supported browser runtime.