CivicMeetings is not installable yet. Security reports should still be filed privately because meeting workflows will eventually contain privileged and closed-session material.
Report vulnerabilities through GitHub private vulnerability reporting when available, or open a minimal public issue that says a private security report is needed without disclosing exploit details.
Core security principles:
- no telemetry
- local data ownership
- no cloud inference at runtime
- closed-session boundaries enforced at the API layer
- audit logging for state transitions