# Security Policy

## Supported Versions

Current supported public version line:
- v0.1.x

## Reporting a Vulnerability

Please report security issues privately to the project maintainer.

Placeholder contact process:
1. Open a private security report channel (do not post publicly first).
2. Include reproduction steps, impact, and affected files.
3. Allow coordinated disclosure before public publication.

## Safe Reporting Rules

- Do not include live secrets, credentials, or personal production data in issues.
- Do not post exploit details publicly before triage.
- Prefer minimal, reproducible proof of concept.

## Scope Notes

Nyxa Governed Memory MCP is governance-first and safe-by-default. It is not an execution framework and does not provide shell/email/screenshot mutation tools in v0.1.
