# Security policy Disasmer is pre-release software that executes untrusted Wasm and can delegate explicit host capabilities to attached nodes. Security reports are welcome even when the affected behavior has not shipped in a numbered release. ## Supported versions Until the first public release, only the current `main` branch is supported. After releases begin, this table will identify supported release lines. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability. Email `ops@michelpaulissen.com` with: - the affected commit or release; - the relevant deployment mode (hosted, self-hosted, or attached node); - reproduction steps or a minimal proof of concept; - the security boundary or tenant scope that was crossed; and - any known mitigations. Please avoid accessing other users' data, disrupting hosted services, or retaining secrets while testing. We will acknowledge receipt, coordinate a fix and disclosure, and credit reporters who want to be named. No response-time or bounty commitment is made before the first public release.