Security fixes are applied to main and, when practical, to the latest tagged
registry snapshot. Historical commits and older snapshots are immutable
publication records and are not maintained releases.
Do not open a public issue for a suspected vulnerability, exposed secret, private-data disclosure, or publication-control bypass.
Use GitHub’s private vulnerability reporting for this repository when the
Report a vulnerability button is available on the Security page. If it is
not available, email hello@vizai.io with the subject
SECURITY: business-registry.
Include only what is necessary to reproduce and assess the issue:
Do not include live credentials, unrelated personal data, or destructive test results. If sensitive material is already public, provide its location rather than duplicating it.
Public factual corrections, business disputes, removal requests, and ordinary data-quality concerns are not security vulnerabilities. Use Correction, dispute, and removal.
These are operational targets, not guarantees:
VizAI asks reporters to avoid privacy violations, service disruption, social engineering, and data destruction. Good-faith research that follows this policy will be handled through coordinated disclosure.