# Security Policy & Vulnerability Disclosure
Rivox takes supply-chain integrity, process isolation, and build coordination security seriously.
---
## Supported Versions
| 1.0.x | Yes | Active Support |
| < 1.0 | No | End of Life |
---
## Reporting a Vulnerability
If you discover a security vulnerability in Rivox (including path traversal, sandbox escape, CAS poisoning, integer overflow, or provenance forgery), please report it confidentially.
**Do NOT report security vulnerabilities through public GitHub issues.**
Instead, please email a detailed report to:
📧 **aaryan28rwt@gmail.com**
### What to Include in Your Report:
- A detailed description of the vulnerability and affected component (e.g. Ingestion Adapter, CAS, Sandbox, Provenance Generator).
- Steps to reproduce or a Proof-of-Concept (PoC) repository/script.
- Potential impact (e.g. host filesystem write access, unauthorized network outbound egress inside sandbox).
### Response Timeline
- **Initial Acknowledgment**: Within 24 hours.
- **Triage & Impact Assessment**: Within 72 hours.
- **Security Patch Release**: Targeted within 7 to 14 days depending on severity.
Thank you for helping keep Rivox and its supply-chain ecosystem secure!