# Security Policy ## Supported versions | Version | Supported | |---------|--------------------| | 0.9.0 | :white_check_mark: | | 0.8.1 | :x: | ExoSnap is pre-v1 preview software. Only the latest release receives security attention. ## Reporting a vulnerability **Do not report security vulnerabilities through public GitHub issues.** Instead, please report them via email to: > github@codexo.de Include as much detail as possible: - Affected version - Steps to reproduce - Impact assessment - Any suggested mitigations You should receive an acknowledgement within 72 hours. If the issue is confirmed, a fix will be prepared and released as soon as possible. ## Scope Security reports are welcome for: - The ExoSnap application binary - The installer (MSI) - Build and packaging scripts that affect released artifacts Out of scope: - Issues that require physical access to a running session - Theoretical attacks with no practical exploit path - Third-party library vulnerabilities (please report those upstream) - Social engineering or phishing ## Disclosure We follow coordinated disclosure. Once a fix is released, we will credit the reporter (unless they prefer anonymity) and publish a brief advisory.