# Security Policy
## Supported Versions
libcrux is still pre-release and does not support any specific versions yet.
## Reporting a Vulnerability
Use the private [Github vulnerability reporting](https://github.com/cryspen/libcrux/security)
or send an email to [security-reports@cryspen.com](mailto:security-reports@cryspen.com)
PRs or issues that do not follow the security policy will be closed.
## Security Advisories
We believe that any bug in a cryptographic library is a potential security vulnerability.
Starting February 2026, we will issue GitHub security advisories for any releases whose CHANGELOG
includes bug-fixes, and encourage our users to upgrade.