If you discover a security vulnerability in LexShield, please do not open a public issue.
Contact Arwaz Khan via LinkedIn: linkedin.com/in/arwazkhan023
Include a description of the vulnerability, steps to reproduce, and the potential impact. You will receive a response within 72 hours. If the issue is confirmed, a fix will be prioritized and a patched release will be published with credit to the reporter if desired.
LexShield fetches from public official regulatory sources. It does not handle personal data, user accounts, or payment information. The primary security surface is API key handling in config files. Do not commit your .env files to version control.