# Security Policy

## Supported version

The latest release on the default branch is supported.

## Reporting a vulnerability

Do not include real employee salary information, payslips, account details, or other personal data in a public issue.

Report security concerns privately to the repository owner. Include:

- A description of the issue.
- Steps to reproduce it using synthetic data.
- The affected file or function.
- The potential impact.

This application is intentionally client-side and does not transmit entered payroll data. Contributions that add analytics, storage, external APIs, or network requests require an explicit privacy and security review.
