| Version | Supported |
|---|---|
| 3.x | Yes |
| < 3.0 | No |
Please report security vulnerabilities to: security@citadelcloudmanagement.com
Do NOT open a public issue for security vulnerabilities.
- 24 hours: Acknowledge receipt
- 72 hours: Provide initial assessment and remediation plan
- 7 days: Release fix for critical vulnerabilities
- 30 days: Release fix for non-critical vulnerabilities
We follow coordinated disclosure. We ask that you:
- Report the vulnerability privately
- Allow reasonable time for a fix
- Do not exploit the vulnerability beyond proof of concept
- Do not disclose publicly until a fix is available
We will credit reporters in our security advisories unless anonymity is requested.