# Security policy

HeavyHaul Agent takes reports of security problems seriously.

## Reporting a vulnerability

Email **security@heavyhaulagent.com** (or support@heavyhaulagent.com) with:

- what you found and where (URL, request, or file),
- steps to reproduce,
- the impact you believe it has.

We acknowledge reports within **2 business days** and aim to fix confirmed
issues within **30 days**, sooner for anything that exposes customer data.
Please do not access or modify data that is not yours, and do not run
denial-of-service tests against the live site.

## Scope

- https://heavyhaulgbt.com and the HeavyHaul Agent application in this repository.
- Not in scope: third-party services we use (Supabase, AWS, ZeptoMail,
  Synchron Permits, the HeavyHaul GPT service); report those to the vendor.

## What is in place

See `docs/SECURITY-CONTROLS.md` for the controls this application implements
(authentication, authorization, session handling, transport security,
rate limiting, audit and security event logging, dependency updates) and the
operating procedures around them.
