# Security Policy

## Supported versions

Security fixes are applied to the latest release of this package.

## Reporting a vulnerability

Please report security issues privately to the maintainer. Do not open public issues for vulnerabilities that could expose application secrets or enable attacks.

This package is a **read-only posture auditor**. It must never log or render raw secret values from `.env` or config.
