# Security Policy ## Reporting a vulnerability Please report security issues privately to **guy@animoflow.ai** — do not open a public issue. You'll get an acknowledgment within a few days. ## Scope notes - This code runs the hosted demo at animoflow.ai / the AnimoFlow Space. Issues in the API contract itself are best reported against animoflow-api, but reports here reach the same maintainer. - The Space executes no code from prompts or uploads; generated animation leaves as data files (FBX/GLB) only. - Prompts are logged for service health; no accounts or PII are stored. There is no bug bounty program at this time.