If you discover a security vulnerability in Policai, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please email the maintainers directly or use GitHub's private vulnerability reporting.
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation plan within 7 days.
This policy covers the Policai application code and its deployment configuration. It does not cover third-party services such as Vercel — please report vulnerabilities in those services to their respective maintainers.
Only the latest version on the main branch is actively maintained.