PARALLAX handles visual evidence and operational workflows. If you discover a security vulnerability, please report it privately.
Do not open a public issue. Send details to [email protected].
We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if applicable)
- The PARALLAX engine (
server/) - The MCP tool layer (
server/mcp.ts) - The evidence ledger (
server/engine.ts) - Vision model adapters (
server/vision.ts)
- Vulnerabilities in third-party dependencies (report to the respective maintainers)
- Theoretical attacks requiring physical access to the server hardware
We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.