# Security policy

## Supported versions

| Version | Supported |
| --- | --- |
| 0.1.x | yes |

## Reporting a vulnerability

Use GitHub private vulnerability reporting for
`baselabs/charter_agreement_protocol`. Do not open a public issue containing
an exploit, credential, private key, production data, tenant data, or
unreleased vulnerability detail.

A report should identify the affected commit or package version, the violated
property, a minimal value-free reproduction, and the expected fail-closed
result.

## Security boundary

The package is currently a scaffold and ships no runtime behavior. The
protocol's security boundary is stated here as its surface lands.
