The 0.1 prerelease receives best-effort security fixes and has no promised SLA.
Do not report vulnerabilities in a public issue. Use GitHub private vulnerability
reporting on the dlamaro96/recordlane repository once the repository exists.
Until publication verifies that channel, security-reporting readiness is
BLOCKED; do not send secrets or exploit data to an invented email address.
Never include real records, access tokens, passwords, private keys, or customer URLs in a report. The threat model documents privileged-administrator and connector trust boundaries.