# Security policy

## Reporting a vulnerability

Do not open a public issue for a vulnerability, credential, private identifier, publication-gate
bypass, or accidental disclosure. Use the repository host's private vulnerability-reporting channel
once hosting is established. Until then, contact Stephen Reed through a previously verified private
channel.

Include the affected file or revision, expected and observed behavior, minimal reproduction, impact,
and whether any restricted material may already have been exposed. Do not include unnecessary secret
or personal data.

## Scope

Reports about the static generator, verification tooling, release controls, dependency integrity,
and accidental-publication paths are in scope. General disagreement with a research thesis belongs
in the research discussion process unless it also exposes a security defect.

## Response

The custodian will acknowledge a report, preserve evidence, assess exposure before remediation, and
record public corrections when disclosure is safe to describe. No response-time guarantee is made.
The absence of a published vulnerability is not evidence that none exists.

