# Security Policy
## Supported Versions
We adhere to Semantic Versioning 2.0.0. Security updates are provided for the current major version.
| 1.x.x | :white_check_mark: |
| < 1.0 | :x: |
## Reporting a Vulnerability
**Do not open a public GitHub issue for security vulnerabilities.**
If you discover a security vulnerability in ReasonKit, please report it privately:
1. **Email:** <security@reasonkit.sh>
2. **Response Time:** We are committed to responding to security reports within 48 hours.
3. **Process:**
- We will investigate and verify the issue.
- We will develop a patch.
- We will release a security advisory and a patched version.
- We will acknowledge your contribution (with permission).
## Responsible Disclosure
We ask that you:
- Give us reasonable time to fix the issue before making it public.
- Do not exploit the vulnerability to view data, modify data, or disrupt service.
- Do not attack our users or infrastructure.
## Security Audit
This project has undergone internal security audits. However, users should conduct their own security assessment before deploying in sensitive environments.