# Security Policy Do not disclose a suspected Vault Prospector vulnerability in a public issue, discussion, package review, pull request, or social-media post. Email with the subject `Vault Prospector security report`. Do not send live credentials, tokens, private keys, certificates, secret values, unredacted diagnostics, or sensitive screenshots. Use synthetic reproduction data and ask for a secure transfer method if sensitive evidence is necessary. The maintainer targets acknowledgment within three business days and an initial assessment or request for more evidence within seven business days. These are Preview operational targets, not a contractual service-level agreement. Only the latest published Preview is supported for security fixes. Affected immutable artifacts are never silently replaced; remediation is published as a new version with containment and rotation guidance when applicable.