# Security Policy Nimbus takes security seriously. The full security model, threat model, and invariant catalogue (I1–I30, with I28 reserved) live in [`docs/SECURITY.md`](../docs/SECURITY.md) and the central [nimbus-security](https://github.com/nimbus-agent/nimbus-security) repository. ## Reporting a vulnerability Please **do not** open a public issue for security reports. Use GitHub's private vulnerability reporting — the **Security** tab → [**Report a vulnerability**](https://github.com/nimbus-agent/Nimbus/security/advisories/new). It is the only reporting channel: Nimbus publishes no security email address and no PGP key, because a solo maintainer's unmonitored inbox drops reports silently. Nimbus is maintained by one person as a side project, so there is no guaranteed response time and no SLA. Reports are typically read within a week and prioritised by severity, and we will agree a coordinated-disclosure timeline with you. See the full policy, scope and safe-harbor terms in [nimbus-security](https://github.com/nimbus-agent/nimbus-security/blob/main/SECURITY.md).