# Security Policy **Status:** Pre-release project maintained by volunteers. Best-effort responses. ## Reporting a vulnerability Please report vulnerabilities via [GitHub Security Advisories](https://github.com/eclaire-labs/eclaire/security/advisories/new). **Do not** open public issues/PRs for suspected vulnerabilities. ## Scope / out of scope - **In scope:** This repository only. - **Out of scope:** Deployment hardening topics (e.g., running on shared hosts, handling untrusted inputs, exposing the service directly to the public internet). See our README “Security Warning” for deployment guidance. _No bug bounty and no SLA._ ## Supported versions Pre-release only: the `main` branch is supported; no backports.