Email security@sqoia.dev with details. We will acknowledge within 48 hours and provide a timeline for a fix.
Do not open a public GitHub issue for security vulnerabilities.
This policy covers the tunnl server, CLI, and protocol as distributed from this repository.