The latest minor release of cpz-quant receives security fixes.
Please report suspected vulnerabilities privately to contact@cpz-lab.com with "SECURITY" in the subject line. Do not open a public issue for security reports.
We will acknowledge receipt within 3 business days and keep you informed of progress. Please give us a reasonable window to release a fix before public disclosure.
Note that cpz-quant is a pure computation library: it performs no network I/O, file I/O, or credential handling. Reports about the CPZAI hosted services or the cpz-ai SDK should also go to contact@cpz-lab.com.