# Security Policy ## Supported Versions We actively maintain the latest stable release of Netcatty. Security fixes are applied to the current release only. | Version | Supported | | ------- | ------------------ | | Latest | :white_check_mark: | | Older | :x: | ## Reporting a Vulnerability If you discover a security vulnerability in Netcatty, **please do not open a public GitHub Issue**. Instead, report it privately via one of the following methods: - **GitHub Private Vulnerability Reporting**: Use the [Security tab](https://github.com/binaricat/Netcatty/security/advisories/new) to submit a private advisory. - **Email**: Send details to support@netcatty.com. - **GitHub Issues** (for non-sensitive security concerns only): https://github.com/binaricat/Netcatty/issues Please include the following details in your report: - A description of the vulnerability - Steps to reproduce the issue - The potential impact - Any suggested mitigation or fix ## Response Timeline We aim to: - Acknowledge receipt within **3 business days** - Provide a status update within **7 business days** - Release a patch as soon as possible depending on severity ## Scope This policy applies to the Netcatty desktop application (`netcatty.app`) and its source code in this repository. Vulnerabilities in third-party dependencies should be reported directly to the respective upstream projects. ## Disclosure Policy We follow responsible disclosure. Once a fix is available, we will publish a security advisory and credit the reporter (unless they prefer to remain anonymous).