# Security Policy

## Scope

CSPKit analyzes Content-Security-Policy text. It does not receive network traffic, execute browser code, or validate live deployment headers. Findings are advisory and should be reviewed against the application's threat model.

## Reporting a vulnerability

Please avoid posting exploitable details in a public issue. Use a private GitHub Security Advisory or another private channel available from the repository owner. Include the affected version, a minimal reproducible policy, expected behavior, observed behavior, and a suggested severity when possible.

Do not include passwords, access tokens, private source code, personal contact details, or production data in a report.

## Maintainer response

Reports will be reproduced with the repository's tests, assessed for impact, and followed by a fix, regression test, and changelog entry when appropriate.
