Built to fail closed.

A gateway that holds provider credentials and customer prompts must be safe by default. Unsafe production configuration refuses to start — loudly, before serving a single request.

Found a vulnerability?

Do not open a public issue. Report it privately per SECURITY.md in the repository, or via the contact page. Key-material handling, auth bypass, tenant cross-talk, and denial-of-wallet are treated as high severity.