# Security Policy

## Reporting a Vulnerability

Do not open a public issue for suspected vulnerabilities or exposed secrets.

Use GitHub's private vulnerability reporting feature for this repository:

1. Open the repository's **Security** tab.
2. Select **Advisories**.
3. Choose **Report a vulnerability**.

Include affected versions, reproduction steps, impact, and any suggested mitigation. Remove real SOC data, credentials, and customer identifiers from reports.

## Supported Versions

Until the first stable release, security fixes are applied to the latest version on the default branch only.

## Operational Notice

RAVENSTRIKE generates detection and response artifacts for analyst review. Do not automatically execute generated queries, suppression changes, containment actions, or SOAR playbooks without validation and organizational approval.
