# Security Policy
## Supported Versions
| 0.x | Yes |
| < 0.0 | No |
Pre-1.0 projects: only the latest minor is supported.
## Reporting a Vulnerability
**Do not open a public GitHub issue for security vulnerabilities.**
Report privately via one of:
1. [GitHub Security Advisories](https://github.com/urmzd/generative-artifact-protocol/security/advisories/new) (preferred)
2. Email **hello@urmzd.com**
Include:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
### Response timeline
- **Acknowledgment** within 48 hours
- **Initial assessment** within 1 week
- **Fix target** within 90 days of confirmation
### Recognition
Contributors who responsibly disclose vulnerabilities will be credited in the
release notes unless they prefer to remain anonymous.