# Security Policy

Thank you for helping keep this project and its users safe. We take security issues seriously and appreciate responsible disclosure.

## Supported Versions

We generally support the latest release series and the `main` branch. Security fixes may be backported at the maintainers' discretion when feasible.

## Reporting a Vulnerability

-   Please do not open public GitHub issues for security reports.
-   Email [julien@opnform.com](mailto:julien@opnform.com?subject=Security%20Vulnerability%20Report%20for%20OpnForm&body=Please%20describe%20the%20vulnerability%20in%20detail%20including%20affected%20version%2C%20steps%20to%20reproduce%2C%20impact%2C%20and%20any%20suggested%20mitigations.) with details.

When reporting, include as much information as possible:

-   Affected version(s) and environment
-   Steps to reproduce, proof-of-concept, or exploit scenario
-   Impact assessment and potential severity
-   Any suggested mitigations or workarounds

## Safe Harbor

We consider research conducted under this policy to be authorized. If you follow this policy:

-   We will not pursue legal action
-   We will not request law enforcement investigations

Please:

-   Avoid privacy violations, data exfiltration, or service disruption
-   Do not access more data than necessary to demonstrate the vulnerability
-   Do not perform actions that could harm users or infrastructure

## Out of Scope Examples

-   Reports from automated scanners without an exploitable impact
-   Missing security headers that do not lead to a concrete vulnerability
-   Clickjacking on pages without sensitive actions
-   Use of known-vulnerable dependencies without a proven exploit path in this project

## Public Disclosure

We prefer coordinated disclosure. Please contact us first and give us reasonable time to investigate and address the issue before any public disclosure.
