%% SCRAP: archive/legacy/phase-1/Reference/SECURITY %% SOURCE: docs/working/archive/legacy/phase-1/Reference/SECURITY.md %% STATUS: HISTORICAL %% FITS: none %% EDITORIAL: lifted — prose rewritten to press voice \section*{Security Policy (Pre-ACL Era)} The original StarForth security policy addressed vulnerability disclosure through a contact-email mechanism with a 72-hour response commitment. This policy predates the word-level ACL system (\texttt{capsules/ACL.4th}, Phase~6 complete) that now governs runtime security enforcement. The contact information and disclosure procedure described here may no longer reflect current project practice. %% TODO(bob): Confirm whether a current public security policy exists and %% where it lives. The ACL system covers runtime security; a disclosure %% policy for external reporters is a separate concern.