# Security Policy

## Supported versions

| Version | Supported |
|---------|-----------|
| 1.x (mainnet / `master`) | Yes |

## Reporting a vulnerability

Email **hello@doggybagg.cc** with:

- description and impact
- reproduction steps / PoC (non-destructive preferred)
- affected URL or commit

Please **do not** open a public GitHub issue for undisclosed vulnerabilities.

We aim to acknowledge within **72 hours** and provide a remediation timeline after triage.

## Scope

In scope: SQLGuard HTTP/MCP APIs on production hosts, certificate verification logic, credit/payment enforcement.

Out of scope: third-party facilitators, blockchain consensus bugs, denial-of-service via enormous legitimate paid traffic without coordination, social engineering of unrelated accounts.

## Safe harbor

Good-faith research that avoids privacy violations, data destruction, and service disruption, and that promptly reports findings, is appreciated and will not be treated as a Terms violation.

## Contact

hello@doggybagg.cc  
`https://sqlguard.io/.well-known/security.txt`
