# Security policy

## Supported versions

Until the first stable release, security fixes are applied to the latest
published version only.

## Reporting a vulnerability

Please use
[GitHub private vulnerability reporting](https://github.com/SI-RUI-ZHANG/pi-x-search/security/advisories/new)
rather than opening a public issue. Do not include real access tokens, refresh
tokens, API keys, account identifiers, or raw authenticated responses in a
report.

Relevant reports include credential exposure, requests that can leave the
official xAI origin, terminal or prompt injection through returned content,
unbounded response handling, and authentication fallback that could cause
unexpected billed usage.

You should receive an acknowledgement through the advisory within seven days.
