# Security ## Reporting vulnerabilities Email **security@rakazo.com** only. Do not open public GitHub issues for security bugs. Please include: - Steps to reproduce - Impact (what an attacker could do) - Whether the issue is already public We will acknowledge your report and work on a fix. Please do not file a public issue for unfixed vulnerabilities. ## Other contact - General support: **support@rakazo.com** - Maintainer: **elie@rakazo.com** ## Scope This policy covers the Rakazo self-hosted product in **this repository**. Out of scope: - Third-party AI models and their APIs - Composio, E2B, and other external services - Operator misconfiguration (exposed secrets, open databases, weak passwords) ## Supported versions We support security fixes on the current `main` branch and the latest release (beta). There is no bug bounty program at this time.