This policy covers every Scenario repository without its own SECURITY.md, and
the Scenario platform: app.scenario.com, api.cloud.scenario.com and
mcp.scenario.com.
Never report a vulnerability in a public issue, pull request or discussion. Report it privately:
- Use Report a vulnerability on the affected repository's Security tab, when it is offered.
- Or email support@scenario.com with "security" in the subject.
Include the affected product and version, reproduction steps and the impact you observe. Use your own account and synthetic data; do not access other users' data or degrade the service. We acknowledge reports and follow up through the same private channel.
API keys and secrets, bearer tokens and signed asset URLs are credentials. Never paste them into a public issue or pull request. If one is exposed, revoke it in app.scenario.com and tell us privately.