# Security Policy

- **Reporting**: Report suspected vulnerabilities privately to _security@qbitflow.app_.
- **Supported Versions**: We support the latest minor release and the previous one.
- **Patch SLAs**: Critical issues patched within 72 hours; high within 7 days.
- **Disclosure**: Coordinated disclosure with CVE where appropriate; advisories posted in RELEASE_NOTES.md.
- **Integrity**: Official SDK builds are signed. Do not use unsigned or tampered builds in production.
