# Security

Report vulnerabilities privately to `contact@samedaydesk.com` with the subject
`agent-payment-policy security report`.

Please include the affected version, a minimal reproduction, the expected
security property, and the observed result. Do not include real wallet private
keys, API credentials, or customer data.

This candidate has no wallet executor. Findings involving an application that
adds signing, custody, RPC access, redirects, DNS resolution, or persistence
must state that integration boundary explicitly.
