Security

paperjet treats render isolation, secret hygiene, and supply-chain integrity as non-negotiables. The render path runs in a sandboxed Container with a custom Typst World, a 5-second wall-clock timeout, and OS-level seccomp + landlock + cgroup limits.

Reporting a vulnerability

Email [email protected]. Acknowledged within 48 h, triaged within 5 business days. Full disclosure policy lives in the SECURITY.md.

What you should know