# Security Policy ## Reporting a Vulnerability If you discover a potential security issue in this project, please **do not** create a public GitHub issue. Instead, report it privately: - **Email:** [kiro-crew-security-support@amazon.com](mailto:kiro-crew-security-support@amazon.com) - **Subject prefix:** `[SECURITY]` Please include: - A description of the vulnerability - Steps to reproduce - Potential impact - Suggested fix (if any) We will acknowledge your report within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues. ## Supported Versions Only the latest release is actively supported with security patches. We recommend always running the most recent version. ## Scope This policy covers the Kiro Crew source code and its bundled dependencies. It does not cover third-party services (LLM providers, etc.) that Kiro Crew connects to.