# Security Policy
## Supported Versions
Security fixes are provided for the latest code on the default branch (`main`).
| `main` (latest) | :white_check_mark: |
| Older commits / releases | :x: |
## Reporting a Vulnerability
Please report suspected vulnerabilities privately through GitHub Security Advisories:
- https://github.com/Cassin01/multi_agent_control_tower/security/advisories/new
Do not open public issues for security vulnerabilities.
When possible, include:
- a description of the issue and potential impact
- reproduction steps or a proof of concept
- affected version/commit and environment details
- any suggested remediation
## Response Expectations
Maintainers will aim to:
- acknowledge new reports within 7 business days
- investigate and validate the issue
- coordinate a fix and disclosure timeline
Response and remediation timelines may vary based on severity and maintainer availability.