Report suspected vulnerabilities privately to security@leadmagic.io. Share a minimal, sanitized reproduction and affected version. Do not post credentials, access tokens, personal contact records, customer data, private logs, or exploit payloads in public issues.
Use the official links in the repository README and LeadMagic documentation to verify installation sources. Third-party projects and references do not imply affiliation or endorsement.
Keep credentials in a secret manager or the client's supported authentication flow. Public examples must use synthetic data. If a real credential has been published, revoke or rotate it with its issuing service; deleting a file does not invalidate a credential or erase Git history.
Security controls, service commitments, and contractual terms are defined by the applicable published policies and agreements. This repository does not claim certification, universal legal compliance, or guaranteed security.