# Security Policy

## Supported Versions

We follow the [SemVer](https://semver.org/).

The latest version released is the only version that will receive security updates, generally as a **PATCH** release unless a security issue requires a functionality change in which requires a minor/major version bump.

## Reporting a Vulnerability

For security reasons, the following are acceptable options for reporting all security issues.

1. Via a Privacy Portal support ticket within the [Privacy Portal app](https://app.privacyportal.org/support).
2. Via PGP encrypted email to the Privacy Portal support [Learn More](https://privacyportal.org/support).
3. Via a private [security advisory](https://github.com/privacyportal/wp-privacy-portal-sso/security/advisories) notice.

Please disclose responsibly and not via public GitHub Issues (which allows for exploiting issues in the wild before the patch is released).
