# Security policy ## Supported versions Security fixes are made for the latest released package version. While the SDK is pre-1.0, upgrade to the latest beta before reporting a suspected issue. ## Reporting a vulnerability Please report vulnerabilities privately through [GitHub Security Advisories](https://github.com/alexhopeoconnor/binarylane-dotnet/security/advisories/new). If private reporting is unavailable, open a minimal public issue that asks for a private contact channel and does not disclose exploit details. Do not include any of the following in a report, issue, pull request, log, or sample: - BinaryLane bearer tokens or authorization headers; - account email addresses, invoices, or billing data; - passwords, password reset payloads, SSH private keys, or `user_data`; - private IP addresses, server names, DNS records, or raw response bodies that are not essential to demonstrate the problem. Maintainers aim to acknowledge a report within seven days and will coordinate a fix and disclosure timeline with the reporter.