# Security Policy ## Reporting a vulnerability Please do **not** report security vulnerabilities through public GitHub issues, discussions, or pull requests. Instead, report them privately through one of these channels: - Email: **[security@truefoundry.com](mailto:security@truefoundry.com)** - GitHub: use [private vulnerability reporting](#) on this repository Please include as much of the following as you can: - A description of the vulnerability and its impact - Steps to reproduce, or a proof of concept - Affected versions or deployment modes (standalone / multi-replica / Helm) - Any suggested mitigations ## What to expect - We will acknowledge your report within **3 business days**. - We will keep you informed as we investigate and work on a fix. - We will credit you in the release notes when the fix ships, unless you prefer to remain anonymous. ## Supported versions Security fixes are applied to the latest release. We recommend always running the most recent version.