# Security policy TurnScope reads local Codex session metadata and can display prompts, reasoning summaries, tool inputs, and tool outputs. Treat screenshots and copied inspector content as sensitive. Report security issues through the repository's **Security → Report a vulnerability** flow. Do not attach real rollout files, access tokens, private paths, or proprietary tool output to a public issue; use a minimal synthetic fixture instead.