Report a suspected vulnerability privately to
hello@origin89.com with the subject
Origin89 security report. Do not put credentials, pairing keys, private site
details or a working exploit against an installation in a public issue.
Include the affected component and revision, impact, reproduction steps and a minimal redacted example. State whether the issue was observed in a simulator, on an isolated bench or on installed equipment. Test only systems you own or have permission to assess; an isolated fixture is preferable to actuating a working site.
Origin89 is in development. There is no published supported-release matrix, response-time commitment or bug-bounty program yet. Coordinate disclosure with the maintainers through the private report before publishing exploit details.
For ordinary bugs without security impact, use the issue templates. A security report is not authorization to change the state of equipment.