Please do not open a public issue for security vulnerabilities, leaked credentials, backend abuse paths, or privacy-impacting bugs.
Report security issues by email: its.hsichen@gmail.com
Include:
- Affected area: iOS, web, Worker API, deployment, or documentation
- Steps to reproduce
- Expected impact
- Any relevant request IDs, endpoints, or logs
Security reports are welcome for the current main branch and the official
OnTrack service at ontrack.hsichen.dev.
Do not run disruptive testing against the production service. For load testing, scanner testing, or exploit validation, use your own fork and deployment unless you have coordinated first.