Signed-off-by: David Anderson <[email protected]>
@@ -0,0 +1,8 @@
+# Security Policy
+
+## Reporting a Vulnerability
+You can report vulnerabilities privately to
+[[email protected]](mailto:[email protected]). Tailscale
+staff will triage the issue, and work with you on a coordinated
+disclosure timeline.