# Security Policy ## Disclosure Policy If you discover a security vulnerability in this project, please do not publicly disclose it (including in public Github issues) until we have had a chance to investigate and address it. Please report security vulnerabilities to us privately via email to [secluso@proton.me](mailto:secluso@proton.me). If possible, please encrypt your message using the PGP key of one of the project co-founders: * Ardalan Amiri Sani * public key: https://github.com/arrdalan.gpg * Key fingerprint: 1A9A1BA3090FA78E946DC0C0301497925DCCE876 * John Kaczman * Public key: https://github.com/jkaczman.gpg * Key fingerprint: 7785755F1A24FF04CE0E12575DF5E79230C57C4A Please include as much information as possible: * Description of the issue * Steps to reproduce * Proof of concept * Potential impact We will try to provide a response within 3 days.