# Security Policy ## Reporting a vulnerability This library handles personal data, so we take security and privacy issues seriously — especially any path that could cause PII to **leak** (e.g. a placeholder that isn't restored, or sensitive text reaching a downstream service un-anonymized). **Please do not open a public issue for security problems.** Instead, email **security@mobiletic.com** with: - a description of the issue and its impact, - steps to reproduce (a minimal code sample or failing test is ideal), - the package version and Node.js version. We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a fix is released, we're happy to credit you (unless you prefer to remain anonymous). ## Supported versions This project is pre-1.0; security fixes land on the latest published release. We recommend always running the most recent version. ## Scope & disclaimer This library is a **best-effort** pseudonymization aid, not a guarantee of regulatory compliance. LLM and regex detection can miss or misclassify data. Validate against your own requirements (nLPD, GDPR, HIPAA, …) before relying on it for regulated data.