# Security Olivia creates ProcessWire objects and files, runs background workers, fetches optional reference URLs, and can call paid AI providers. Security reports are therefore treated as release-critical. Please do not open a public issue for a vulnerability that could expose secrets, access private network resources, modify site data without approval, bypass ProcessWire permissions, or execute untrusted code. Report vulnerabilities privately to [maxim@smnv.org](mailto:maxim@smnv.org). Include the Olivia, ProcessWire and PHP versions, reproduction steps, expected impact, and any relevant support bundle with secrets removed. You should receive an acknowledgement within seven days. Only the latest published Olivia release receives security fixes. Until Olivia has broader production coverage, use it on development or staging installations and keep current database and file backups.