# Security policy
Do not open a public issue for a suspected credential leak, approval bypass, host-key verification flaw, or remote-code execution vulnerability. Report it privately through the repository's GitHub Security Advisory page and include reproduction steps, affected versions, and impact.
The public alpha currently supports only the latest tagged release. Direct shell access by the same operating-system user, a compromised OS credential store, a compromised SSH agent, malicious remote output designed to evade redaction, and commands explicitly approved by the user are outside SafeHell's protection boundary.