The full security policy for distill - threat model, trust boundaries, and the
private vulnerability-reporting flow - lives in docs/SECURITY.md.
Please report vulnerabilities privately as described there; do not open a public issue for a suspected security problem.