# Security policy This repository holds the landing page for the `open` organisation. It contains no code. The policy below is the security contact for the organisation as a whole; each repo also carries its own `SECURITY.md` with its version and disclosure details. ## Reporting a vulnerability Report privately to — do not open a public issue. If the vulnerability is in a specific repo, say which one. Please include the affected version or commit, a minimal reproduction, and the impact you see. ## Response process This is a solo, best-effort project. There is no SLA and no paid support. What is committed to: 1. Acknowledge within 5 working days. 2. Triage and confirm severity within 10 working days. 3. Develop and test a fix in the affected repo. 4. Credit the reporter in the advisory unless they prefer to stay anonymous. Aim is to disclose within 90 days of the initial report, with the timeline agreed with the reporter. ## Supported versions Every repo here is pre-1.0. Only the latest tagged release of a given repo receives security fixes; upgrade before reporting. Security-relevant fixes are recorded in each repo's `CHANGELOG.md`. ## Out of scope Vulnerabilities in Claude Code itself, in the Claude API, or in third-party dependencies belong with their own maintainers. Report Claude Code issues to Anthropic.