# Security policy Security fixes target the latest release and the default branch. The Host endpoint binds to `127.0.0.1`, checks browser origins, sanitizes file names, limits decoded upload size, and rejects configured inbox paths outside the DSH workspace. Keep it loopback-only unless you add authentication and a separate threat model. Do not publish bot credentials, API keys, session IDs, local configuration, runtime logs, inbox files, or user documents. The optional integration examples contain no credentials and are not part of the npm package. To report a vulnerability, open a minimal GitHub issue asking for a private contact channel. Do not include exploit details or secrets in the public issue.