Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue with a working exploit or recipient data.
Spreadsheet and document parser vulnerabilities, filename or ZIP path issues, unintended network transmission, unsafe HTML rendering, denial-of-service inputs, dependency compromise, and privacy boundary failures are in scope. Version 1.0.0 receives security fixes; there is no promised cadence for feature releases.
Batch Document Studio does not encrypt output ZIPs or certify generated documents. Operators remain responsible for template rights, recipient consent, secure distribution, and deletion of downloaded files.