Do not open a public issue for suspected vulnerabilities, exposed credentials, authentication weaknesses, private-data exposure, or abuse paths.
Email hello@unalabs.cloud with the subject Private security report and include:
- the affected product or URL;
- a concise description and potential impact;
- reproducible steps that do not access other users' data;
- relevant request IDs, timestamps, screenshots, or logs with secrets removed;
- a safe contact method for follow-up.
Una Labs will acknowledge a complete report as soon as practical, triage it by severity, and coordinate remediation and disclosure. Do not perform denial-of-service testing, social engineering, destructive testing, persistence, or data extraction.
Security support applies to currently operated Una Labs products and public organization repositories. Historical demonstrations and archived projects may receive only critical remediation.
Never include credentials, tokens, private keys, session material, or real user information in issues, pull requests, screenshots, or test fixtures.