FlowForge's MVP ships with development-grade identity (the
X-FlowForge-User header) and no built-in authentication — do not expose
the API or console to untrusted networks without putting real
authentication in front of them. See PRD section 22 for the current
security posture.
Please report suspected vulnerabilities privately via GitHub Security Advisories rather than public issues. Include reproduction steps and the affected component (engine, storage, API, console). You should receive a response within a week.