# Security Report TabBot vulnerabilities to **legal@honeypeer.com**. Do not attach bot tokens, vault passphrases, or named-secret values. TabBot does not hold user tokens on HoneyPeer servers. The official origin is https://tab-bot.rest; vault ciphertext still lives in the visitor’s browser. Typical issues are XSS on a TabBot origin, unsafe module import, or documentation that leaks secrets. See `legal/security.md` (also `/legal/security`) and `docs/security/threat-model.md`. Incident handling is in the legal Security page. Hangout: https://join.discord-linux.com — still do not paste secrets there.