# Security Policy
## Supported Versions
| 0.1.x | Yes |
## Reporting a Vulnerability
If you discover a security vulnerability in Daimon, please report it responsibly.
**Do not open a public GitHub issue for security vulnerabilities.**
Instead, please email **jquinn@lexmata.ai** with:
1. A description of the vulnerability.
2. Steps to reproduce.
3. The potential impact.
4. Any suggested fix (if you have one).
You can expect:
- **Acknowledgment** within 48 hours.
- **Status update** within 7 days.
- **Fix or mitigation** targeted within 30 days for critical issues.
We will coordinate disclosure with you and credit you in the advisory (unless you prefer to remain anonymous).
## Scope
This policy applies to the Daimon crate and its first-party code. For vulnerabilities in third-party dependencies, please report them to the upstream maintainer and file an advisory at [RustSec](https://rustsec.org/).