# Security Policy

## Reporting a vulnerability

If you discover a security vulnerability in Lyt, please report it
responsibly:

1. **DO NOT** file a public GitHub issue.
2. Email **office@younndai.com** with:
   - A description of the vulnerability and its potential impact
   - Steps to reproduce, or a proof of concept (if safe to share)
   - Affected versions
   - Suggested severity: **Critical**, **High**, or **Moderate**

Responsible disclosure preserves the safety of every downstream user.

## Response timeline

| Action                  | SLA              |
| ----------------------- | ---------------- |
| Acknowledgement         | 72 hours         |
| Initial assessment      | 7 calendar days  |
| Remediation or advisory | 30 calendar days |

Critical issues are prioritized and may be patched ahead of the stated window
where feasible.

## Supported versions

Lyt is in public **alpha**. Security fixes are applied to the latest published
`alpha` release only. Pin to a released version and update promptly when a new
alpha ships.

## Responsible disclosure

We commit to:

- Acknowledging your report within the timeline above
- Working with you to verify and reproduce the vulnerability
- Coordinating a public disclosure date that gives users time to update
- Crediting you in the security advisory (unless you prefer anonymity)

---

© 2026 MARLINK TRADING SRL (YounndAI).
