# Security Policy ## Reporting a Vulnerability We take the security of NexQuant seriously. If you believe you have found a security vulnerability, please report it responsibly. **Please do not report security vulnerabilities through public GitHub issues.** ### How to Report 1. **Open a private security advisory** on GitHub: https://github.com/TPTBusiness/NexQuant/security/advisories 2. Provide a detailed description of the vulnerability 3. Include steps to reproduce if possible 4. We will respond within 48 hours ### What to Expect - We will acknowledge your report within 48 hours - We will investigate and provide updates regularly - Once resolved, we will credit you in the release notes (if desired) - Please allow reasonable time for us to address the issue before public disclosure