# Security Policy ## Supported versions Security fixes are provided according to [SUPPORTED_VERSIONS.md](SUPPORTED_VERSIONS.md). ## Report a vulnerability Do not open a public issue. Use GitHub private vulnerability reporting when enabled, or contact the maintainers through the private channel documented in [SUPPORT.md](SUPPORT.md). Include the affected version, impact, reproduction, and suggested mitigation. Never include live credentials, private prompts, responses, or customer data. Maintainers acknowledge reports within five business days, triage severity, coordinate a fix and disclosure window, and publish an advisory after affected users have a reasonable remediation path. ## Security model The platform is preview-first, additive-only, consent-gated for external actions, secret-reference-only in tracked configuration, and restrictive by default for plugins and MCP. See [Security Guide](docs/security/guide.md) and [Security Response](docs/SECURITY_RESPONSE.md).