This repository is an early architectural proof and has no published stable release or security-support window yet.
Please report suspected vulnerabilities privately to the repository owner. Do not open a public issue containing credentials, event payloads, spool contents, or exploit details. Include the affected revision, reproduction conditions, impact, and any suggested mitigation.
See docs/security-model.md for role separation, secret handling, spool
protection, and denial-of-service boundaries.