# Security Policy

## Supported versions

| Version | Supported |
|---------|-----------|
| 1.x (latest) | Yes |
| < 1.0 | No |

## Reporting a vulnerability

**Please do not open a public issue for security reports.**

Report vulnerabilities privately via:

- Email: [security@example.com]
- GitHub private vulnerability reporting: repository → Security →
  "Report a vulnerability"

## What to include

- Description of the issue and potential impact
- Steps to reproduce or proof-of-concept
- Affected versions
- Suggested fix if you have one (optional)

## What to expect

| Stage | Timeline |
|-------|----------|
| Acknowledgment | Within 72 hours |
| Initial assessment | Within 7 days |
| Fix or mitigation | Severity-dependent; critical issues prioritized |
| Disclosure | Coordinated with reporter after fix is released |

## Scope

**In scope**: the application and its official releases.

**Out of scope**: issues in third-party dependencies (report upstream),
social engineering, physical attacks, DoS via resource exhaustion
already tracked.

## Safe harbor

We will not pursue legal action against researchers who report in good
faith, respect user privacy, and do not access or modify data that is
not theirs.
