This is a private investigative-journalism tool. If you discover a security vulnerability, please report it privately rather than opening a public issue.
Open a private security advisory on this repository, or contact the maintainer directly.
- Backend (FastAPI) authorization/authentication boundaries
- Data handling for uploaded documents/evidence
- Dependency vulnerabilities (also tracked via Dependabot)
Please do not include real investigation data, source-identifying information, or credentials in any report.