# Security Policy ## Reporting a vulnerability Please **do not** open a public issue for security vulnerabilities. Report privately via a **GitHub security advisory** on this repository (Security → **Report a vulnerability**). For non-security questions, use **GitHub Issues** (bugs) or **GitHub Discussions** (questions). We will acknowledge your report, work with you on a fix, and coordinate disclosure. Please include reproduction steps, affected version/commit, and your environment (deployment method, browser/desktop, and whether federation or voice is involved). ## Supported versions Backspace 1.x receives security fixes. Always run the latest release.