# Security policy Report suspected vulnerabilities privately to `security@sandwichhime.com`. Please include the affected Tend version, configuration shape, reproduction, and expected impact. Do not include production credentials or private logs. Tend treats source repositories, release artifacts, configuration, handwritten Caddy templates, and operators as trusted. It treats artifact paths, archives, filesystem state, process output, HTTP responses, and deployment targets as adversarial inputs. It never evaluates configuration as shell code. The preview is not a sandbox and does not make an untrusted repository safe to build. Run `tend package` only for reviewed source. Production configuration must be root-owned and kept outside repositories.