Security
Send security reports privately so there is time to investigate and repair the problem before details become public.
Restless Core
Report suspected vulnerabilities through GitHub’s private vulnerability reporting. Include the affected version or commit, reproduction conditions, likely impact, and a minimal reproduction where practical.
Hosted Restless
Use the verified support or account channel supplied with your hosted access. That channel lets us establish which organisation and environment are affected without asking you to publish sensitive context.
Keep reports private
Do not open a public issue for an undisclosed vulnerability. Never include live credentials, personal information, or production workspace data. Use synthetic or redacted evidence wherever possible.
What happens next
We will acknowledge a valid report, investigate its scope, coordinate a fix, and publish an advisory when disclosure is safe. Restless’s authority boundaries and receipts help investigation, but they do not replace responsible reporting or make any system perfectly secure.