Report suspected vulnerabilities privately to security@trace-flow.dev. This is the contact published on the project's security page. Do not open a public issue containing an exploit, credential, or private data.
Include the affected commit or version, a description of the impact, and reproduction steps using synthetic data. Do not send live credentials or captured user conversations.
Trace Flow is internal development tooling shared as source. There is no supported release matrix or guaranteed response time. Security fixes follow the current development branch; backports are not promised.
This project processes model requests and agent activity, which can contain sensitive information. Review the capture, retention, redaction, and access settings before connecting your own data. Redaction is not a guarantee that all sensitive content will be removed.