# Security Policy

## Supported state

This repository currently contains documentation, an empty static catalog, and repository-verification code. No Knowledge Pack ingestion, hosted retrieval, authentication, payment, institutional tenant, PHI processing, or autonomous action capability is operational.

## Reporting a vulnerability

Do not disclose a vulnerability, secret, private record, or suspected sensitive-data exposure in a public issue.

Report privately to:

```text
robert@nurse-ai-os.org
```

Include:

- affected URL, file, commit, or version;
- reproducible steps that do not expose additional people or data;
- observed and expected behavior;
- potential impact;
- any immediate containment already taken.

Do not include PHI, credentials, private keys, access tokens, or unnecessary personal information in the report. If a finding involves sensitive data, describe the location and minimum necessary evidence rather than copying the data.

## Response priorities

1. protect people and stop exposure;
2. quarantine or disable affected distribution;
3. preserve proportionate evidence;
4. investigate exact versions and derivatives;
5. correct or recall;
6. verify removal and document the bounded restart decision.

This policy is not a bug-bounty promise, service-level agreement, compliance certification, or authorization to test third-party systems.
