# Security policy

Ad+Card objects can influence identity, rewards, and settlement. Treat signature bypasses, linkability, replay, receipt overclaiming, and forbidden-field leakage as security issues.

## Reporting

Once this repository is public, use GitHub’s private vulnerability-reporting flow for sensitive reports. Do not open a public issue containing an exploit, personal data, credentials, private evidence, or production identifiers.

Before public vulnerability reporting is enabled, contact the repository owner through a previously verified private channel and share only the minimum reproducible detail.

## Supported versions

No stable version is supported yet. `adcard/0.1` is a draft and may change. Security corrections will be documented in the draft changelog and test vectors.

## Out of scope

This repository does not operate a wallet, instrument, market, escrow, or settlement service. Vulnerabilities in a particular implementation belong with that implementation unless they expose an ambiguity or unsafe default in the protocol itself.
