# Security policy

## Reporting a vulnerability

Please report suspected vulnerabilities privately through [GitHub private vulnerability reporting](https://github.com/dantetekanem/pi-agentic-search/security/advisories/new). Do not open a public issue for an unpatched vulnerability.

Include the affected version, a minimal reproduction, impact, and any relevant environment details. The maintainer will acknowledge the report and coordinate a fix or disclosure through that private report.
