Please report suspected vulnerabilities privately by emailing support@botnest.app.
Include the affected component, reproduction steps, impact, and any relevant request identifiers. Do not include passwords, access tokens, Telegram bot tokens, personal data, or other secrets unless we explicitly arrange a secure transfer method.
Please do not open a public issue for an unpatched vulnerability. We will acknowledge a complete report as soon as practical, investigate it, and coordinate disclosure after a fix is available.
Service availability incidents are published at status.botnest.app.