# Security Policy Sea-Haven-Industries repositories are private and for internal Sea Haven use. ## Reporting a vulnerability If you discover a security vulnerability in any Sea-Haven-Industries repository: - **Do not** open a public issue or describe the vulnerability in a pull request. - Open a private **GitHub Security Advisory** on the affected repository (**Security → Advisories → Report a vulnerability**), **or** - Email **adam@seahavenind.com** with the details. Please include the affected repository and component, reproduction steps, and the potential impact. We aim to acknowledge reports within 2 business days. ## Supported versions These repositories back internal services that are deployed continuously from `main`. Only the currently deployed revision is supported — there are no tagged releases to patch retroactively. Fixes are rolled forward through the normal CI/CD pipeline.