Protecting vulnerable users and private financial data is more important than public proof.
- Do not open a public issue containing an exploitable detail, personal data, passwords, recovery codes, financial records, or private AI conversations.
- Do not attempt to access another person’s record, test with real stolen data, or retain any data encountered accidentally.
- For a sensitive product or security concern, use the private Feedback panel inside Debt World and label the message as a security concern. Include only the minimum reproduction detail and no secrets.
- Public GitHub issues are appropriate for non-sensitive bugs and hardening ideas.
The project is an early public beta. A dedicated private vulnerability-reporting channel will be added before broader-scale promotion.