AEP AI accepts vulnerability reports through this repository's private GitHub Security → Report a vulnerability form. Do not open a public issue or include real credentials, private keys, signed payloads, personal data, or production infrastructure details.
The current main branch and latest Developer Preview release are supported.
Reports should include the affected version, reproduction steps, and impact.
Testing must not target hosted production systems, disrupt service, or access
third-party data. See aepai.org for official project
information.
Send security reports to security@aepai.org when private vulnerability reporting is unavailable. Do not copy Developer or community mailing lists on vulnerability reports.