# Security policy Nextcloud Native handles app passwords, private files, messages, contacts, and other sensitive account data. Please do not report vulnerabilities in a public issue. ## Reporting a vulnerability Report vulnerabilities privately through [GitHub private vulnerability reporting](https://github.com/Obiente/nc-native/security/advisories/new). If that channel is unavailable, contact the Obiente maintainers privately before sharing technical details. Include: - the affected commit or release; - the platform and Nextcloud server/app versions; - the security impact and required preconditions; - minimal reproduction steps using redacted or synthetic data. Do not include live credentials, share tokens, private URLs, message contents, or personal files. We will acknowledge a complete report as soon as practical, coordinate a fix, and credit reporters who want attribution. ## Supported versions The project is currently pre-release. Security fixes target the latest default branch until versioned releases begin.