Email hello@apptelepath.com with SECURITY in the subject, including the SDK version and a minimal reproduction if you have one. Please do not open a public issue for a security report.
AppTelepath is a debugging tool, so reproductions tend to contain exactly what should stay private — workspace keys, captured HTTP traffic, screenshots and recordings, database rows, sandbox files, crash reports with user data. Redact before sending. If a reproduction genuinely requires such data, say so and we will arrange a private channel.
Reports about the hosted service (apptelepath.com, its API and MCP endpoint, the web console) are welcome at the same address — please mention which component is affected.