# Security policy Drive v2 is currently a private personal project and does not accept public vulnerability reports. Security-sensitive behavior must follow the threat model in `docs/threat-model.md` and the architecture baseline. Never commit passwords, API tokens, TOTP secrets, OnlyOffice secrets, database credentials, private keys, or production configuration. If the repository is made public, define a private reporting channel and supported-version policy before the first public release.