RenewalOS Local may handle sensitive insurance and customer information. Do not open a public issue for a suspected vulnerability or include real agency data in a report.
Until a dedicated security mailbox is published, use GitHub's private vulnerability reporting feature for this repository. Include affected versions, reproduction steps, impact, and a minimal test case that contains no real customer data.
Only the newest published release receives security fixes. The project does not currently claim compliance certification or suitability for production use without an operator-led legal, privacy, and security review.