# CapsNav security policy

## Supported versions

Security fixes are provided for the current signed stable CapsNav release and the current hosted website/API. Historical releases that were published under the MIT license remain available under their original terms but do not receive commercial security support.

## Report a vulnerability privately

Use the private security form at <https://capsnav.cospi.cc/feedback.html?topic=security>. Select **Security vulnerability**, include a contact email, and do not open a public GitHub issue until the report has been investigated and a disclosure date has been coordinated.

Useful reports include the affected CapsNav version or URL, Windows version, prerequisites, minimal reproduction steps, expected and actual behavior, security impact, and sanitized screenshots or logs. Do not send passwords, full License Keys, signing material, payment-card data, identity documents, access tokens, or unrelated customer data.

The maintainer aims to acknowledge a credible report within one business day, complete an initial severity assessment within three business days, and provide a status update at least every seven days until resolution. Complex fixes may take longer. CapsNav does not currently operate a paid bug-bounty program.

## Research boundaries

Use accounts and devices you control. Do not perform denial-of-service testing, high-volume automated scanning, social engineering, physical attacks, payment fraud, persistence on systems you do not own, or access to another person's data. Stop testing and report immediately if you encounter customer data, credentials, signing material, or a way to affect production availability.

After a fix is available, coordinate public disclosure with the maintainer so customers have a reasonable opportunity to update. The report, evidence, affected versions, remediation, release identifier, and disclosure decision should be retained with the incident record.
