Email info@gl-solutions.ai with a description of the issue, steps to reproduce, and the affected repository or URL.
Where a repository has GitHub private vulnerability reporting enabled, prefer its Security → Report a vulnerability form — the report stays private and tracked from the start.
Do not open a public issue for a suspected vulnerability.
- Acknowledgement within three business days.
- An assessment and a remediation plan for confirmed issues.
- Credit in release notes if you want it — say so in your report.
This policy is the default for every repository in the GL-Solutions-AI organization. Client-engagement repositories may add their own security contacts on top of it; they never replace it.