# Security Policy
## Reporting a vulnerability
Email **mohamed@riven-labs.com** with a description of the issue, the affected version, and reproduction steps.
We do not currently run a bug bounty program. We acknowledge serious reports within 48 hours and ship a fix or mitigation within 14 days for confirmed issues. Critical issues (RCE in the parser, sandbox escape, anything that lets a hostile input run code or read arbitrary memory) get same-week turnaround.
Please don't open public issues for security reports.
## Supported versions
The most recent minor release receives security fixes. Older versions do not.
## Disclosure
We coordinate disclosure with the reporter. Default timeline is 90 days from initial report, or earlier if a fix ships sooner. We credit reporters in the release notes unless they ask otherwise.