Legilo runs entirely in the visitor's browser, sets no cookies and sends no data to any server. Still, if you find a security issue (XSS via configuration parameters, header injection in the PHP router, or anything else), please report it privately.
Contact: service@legilo.eu
Please do not open a public issue for security reports. You will get a response within a few days; fixes are published as soon as possible.