# Security Policy This is an independent, community-developed ACAP package, provided on a best-effort basis. It is not an official Axis Communications product. ## Reporting a vulnerability Please report security issues privately rather than in a public issue: - Use GitHub's "Report a vulnerability" (Security > Advisories) to open a private advisory, or - email . Include the affected version (or `.eap` filename), camera model / Axis OS version, a description and its impact, and reproduction steps if available. You can expect an acknowledgement within a reasonable time; please avoid public disclosure until a fix is released. ## Scope Reports about this ACAP's own wrapper code, configuration handling, and default settings are in scope. Vulnerabilities in bundled upstream projects should also be reported to their respective upstream projects.