This is an absolutely classic indie/startup security fuckup. (1) Have a security contact, (2) publish a GPG key and accept GPG mail, (3) respond promptly with a "security flaw ID".
You literally don't have to do anything more than this --- mechanically --- to get good-faith people not to publish flaws publicly.