# Security Policy

## Supported Versions

| Version | Supported |
|---------|-----------|
| 0.1.x   | Yes       |

## Reporting a Vulnerability

If you discover a security vulnerability in Dino, please report it responsibly.

**Email**: security@usedino.dev

Please include:
- Description of the vulnerability
- Steps to reproduce
- Impact assessment
- Any suggested fix (optional)

## Response Timeline

- **Acknowledgment**: Within 48 hours
- **Initial assessment**: Within 5 business days
- **Fix or mitigation**: Depends on severity, targeting 30 days for critical issues

## Scope

This policy covers:
- `@dino-hq/cli` (npm package)
- The Dino platform API
- All repositories under the [Dino-HQ](https://github.com/Dino-HQ) GitHub organization

## Out of Scope

- Vulnerabilities in third-party dependencies (report these to the upstream maintainer)
- Social engineering attacks
- Denial of service attacks against our infrastructure

## Credit

We credit reporters in our release notes unless they prefer to remain anonymous.
