# Security Policy
## Supported versions
Security fixes are released for the latest tagged version of the SDK (see [GitHub Releases](https://github.com/ElasticEmail/elasticemail-rust/releases)). Please upgrade to the latest tag before reporting an issue.
| 4.2.x | :white_check_mark: |
| < 4.2 | :x: |
## Reporting a vulnerability
**Please do not open a public GitHub issue for security vulnerabilities.**
Report them privately by one of these methods:
- [GitHub private vulnerability reporting](https://github.com/ElasticEmail/elasticemail-rust/security/advisories/new)
- Email **integrations@elasticemail.com** with the subject `Security: elasticemail-rust`
Please include:
- A description of the issue and its impact
- Steps to reproduce, or a proof of concept
- The affected SDK version(s)
We will acknowledge your report, investigate, and keep you updated on the fix. Please give us reasonable time to release a fix before disclosing the issue publicly.
## API key safety
If you think an API key has been exposed (in a commit, log, issue or screenshot), revoke it right away in your [Elastic Email API settings](https://app.elasticemail.com/marketing/settings/new/manage-api) and create a new one.