# Security Policy
## Supported Versions
| 0.2.1 and later | :white_check_mark: |
| < 0.2.1 | :x: |
## Reporting a Vulnerability
The **InterMCP** project takes security vulnerabilities seriously. For details on our threat model, boundary definitions, and limitations, please consult [docs/SECURITY_MODEL.md](docs/SECURITY_MODEL.md).
If you discover a security vulnerability within InterMCP, please **do not open a public GitHub issue**. Instead, submit your confidential disclosure directly to the maintainers:
📧 **Security Contact**: `bharathbr0x@gmail.com`
### Disclosure Guidelines & SLA
- **Response SLA**: Vulnerability reports will be acknowledged within **24 hours**.
- **Encryption**: Email reports are unencrypted by default. If your disclosure contains sensitive proof-of-concept material requiring PGP encryption, please state so in your initial outreach and we will coordinate an encrypted exchange.
- Please include:
- A clear description of the vulnerability and affected components.
- Steps to reproduce or a minimal proof of concept.
- Potential attack vectors and impact assessment.
We will coordinate a private patch and security advisory before public disclosure.