Report vulnerabilities privately through GitHub's security advisories for this repository. Do not open public issues for security problems. Expect an acknowledgement within a week.
What Doubletake protects and what it does not is described in docs/SECURITY.md and docs/THREAT-MODEL.md.