# enviable Security

## LLM-Generated Security Report Policy

Absolutely no security reports will be accepted that have been generated by LLM
agents.

## Supported Versions

Security reports are accepted for the most recent major release with support for
the previous major version ending immediately.

## Reporting a Vulnerability

By preference, use the [Tidelift security contact][tidelift]. Tidelift will
coordinate the fix and disclosure.

Alternatively, Send an email to [enviable@halostatue.ca][email] with the text
`Enviable` in the subject. Emails sent to this address should be encrypted using
[age][age] with the following public key:

```
age1fc6ngxmn02m62fej5cl30lrvwmxn4k3q2atqu53aatekmnqfwumqj4g93w
```

[tidelift]: https://tidelift.com/security
[email]: mailto:enviable@halostatue.ca
[age]: https://github.com/FiloSottile/age
