Do not file public vulnerability details. Use this repository's Security → Report a vulnerability route when available. If it is unavailable, open a minimal issue titled Security contact request without logs, reproduction steps, credentials, source payloads, or other sensitive material; a maintainer will establish a private channel.
Before sharing material, remove API keys, bearer tokens, repository secrets, provider credentials, private market records, proprietary data, customer names, and local paths.
This policy covers the inert Market Intelligence Domain Packs, their conformance and release harnesses, and the reference public-product connector source in this repository. ACE Core runtime issues belong in the ACE Core security process. A production transport injected into the reference connector remains the deploying application's responsibility.
The project is a developer preview and provides best-effort acknowledgement, assessment, and coordinated disclosure without a response-time SLA.