# Security policy — ZeroDevLLC.com

Report suspected vulnerabilities privately to
[hello@zerodevllc.com](mailto:hello@zerodevllc.com). Include the affected
revision, reproduction, impact, and proposed mitigation. Do not publish
credentials, private hosting configuration, or customer data in public issues.

The supported surface is the current reviewed branch and the hosted public
origin. Runtime secrets belong only in Sites settings or ignored local files.
