# Security Policy

## Reporting a Vulnerability

Report suspected vulnerabilities privately through the repository's
[GitHub Security Advisories](https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/security/advisories/new).

Do not disclose suspected vulnerabilities in a public issue, discussion, or
chat channel. Include reproduction steps, the affected file or component, and
the potential impact when possible.

## Security Expectations

- Review generated agent adapters before installing or running them.
- Keep credentials, tokens, tenant identifiers, and customer data out of agent
  definitions and prompts.
- Preserve least-privilege permissions and explicit approval gates when
  adapting workflows across platforms.
