# Security Policy

## Supported Versions

| Version | Supported |
| ------- | --------- |
| 0.1.x   | yes       |

## Reporting a Vulnerability

Do not open public issues for security vulnerabilities.

Preferred path:

1. Open a private GitHub Security Advisory in this repository.
2. Include reproduction steps, impact, and affected versions.
3. Include logs with secrets redacted.

If GitHub Security Advisory is not available, open an issue with title prefix
`[SECURITY]` and minimal detail, then wait for maintainer contact.

## Response Targets

- Initial triage: within 72 hours.
- Status update: within 7 days.
- Fix timeline: depends on severity and exploitability.
