Report security or privacy issues privately to devs@put.io.
Include the affected platform and version or commit: shipping-app reports belong
to the legacy line; rewrite reports belong to next.
Reports should concern this repository, including authentication, access control, credential or private-data exposure, and unsafe request handling. Test only accounts, data, and systems you control. Keep testing non-destructive and low-volume.
Allow time to investigate and fix the issue before public disclosure. We will coordinate disclosure for valid reports.