# Security Policy ## Reporting a vulnerability Please do not open a public issue for an unpatched vulnerability. Use GitHub's private vulnerability reporting when it is available. Otherwise, open an issue requesting a private contact channel without including vulnerability details. Include the affected version, deployment configuration, reproduction steps, impact, and any suggested mitigation in the private report. Fixes and disclosure timing will be coordinated before details are published. ## Supported versions Security fixes target the latest published container image. Operators should keep `/data`, the active local or cloud model store, and the matching integration encryption key backed up together, then upgrade to the newest release before reporting an issue that may already be resolved.