# Security Policy

## Supported Scope

Security reports are accepted for the backend API, frontend app, CI/CD workflows, Docker assets, migrations, and documentation in this repository.

Do not send raw payment card PAN, CVV, seed phrases, private keys, access tokens, customer PII, or bank credentials in a report. Use redacted examples and evidence references.

## Reporting A Vulnerability

Report vulnerabilities privately to the security owner for this project. Include:

- affected component and endpoint
- impact and exploit conditions
- reproduction steps using non-production data
- logs, screenshots, or request samples with secrets and PII redacted
- suggested severity

The project owner should acknowledge reports within 3 business days, triage within 10 business days, and track remediation evidence in the application security dashboard or issue tracker.

## Coordinated Disclosure

Do not publicly disclose a vulnerability until the project owner confirms remediation or agrees on a disclosure date. Testing must not disrupt production systems, attempt fraud, bypass rate limits at scale, access other users' data, or use stolen credentials.

## Evidence

Accepted remediation evidence includes passing CI security scans, DAST reports, penetration test findings and retest letters, key rotation records, configuration screenshots, signed provider/QSA evidence, or audit-event references.
