# Security Policy ## Supported Versions Security fixes are applied to: - The latest code on `main` - The latest App Store release of VVTerm Older versions may not receive security updates. ## Reporting a Vulnerability Please report vulnerabilities privately to: - `vvterm@vivy.company` Use the subject prefix `"[Security]"` and include: 1. A clear description of the issue 2. Steps to reproduce (or proof of concept) 3. Affected version(s), platform(s), and impact 4. Any suggested remediation, if available Please do not open public GitHub issues for security vulnerabilities. ## Response Targets - Acknowledgement: within 3 business days - Initial triage: within 7 business days - Ongoing updates: as fixes are developed and validated ## Disclosure Policy After a fix is available and users have had reasonable time to update, we may publish a public advisory describing: - Affected components/versions - Severity/impact - Mitigation and upgrade guidance We appreciate responsible disclosure and good-faith security research.