# Enviable Security

## LLM-Generated Security Report Policy

Absolutely no security reports will be accepted that have been generated by LLM
agents.

## Supported Versions

Security reports are accepted for the most recent major release with support for
the previous major version ending immediately.

## Reporting a Vulnerability

Prefer creating a [private vulnerability report][advisory] with GitHub.
Alternatively, send an email to [security@enviable.halostatue.ca][email] with
the text `Enviable` in the subject. Emails sent to this address should be
encrypted using [age][age] with the following public key:

```
age1fc6ngxmn02m62fej5cl30lrvwmxn4k3q2atqu53aatekmnqfwumqj4g93w
```

[age]: https://github.com/FiloSottile/age
[email]: mailto:security@enviable.halostatue.ca
[advisory]: https://github.com/halostatue/enviable/security/advisories/new
