--- /dev/null
+# Security Policy\r
+\r
+## Supported Versions\r
+\r
+The .NET Core and ASP.NET Core support policy, including supported versions can be found at the [.NET Core Support Policy Page](https://dotnet.microsoft.com/platform/support/policy/dotnet-core).\r
+\r
+## Reporting a Vulnerability\r
+\r
+Security issues and bugs should be reported privately to the Microsoft Security Response Center (MSRC), either by emailing secure@microsoft.com or via the portal at https://msrc.microsoft.com. \r
+You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your \r
+original message. Further information, including the MSRC PGP key, can be found in the [MSRC Report an Issue FAQ](https://www.microsoft.com/en-us/msrc/faqs-report-an-issue).\r
+\r
+Reports via MSRC may qualify for the .NET Core Bug Bounty. Details of the .NET Core Bug Bounty including terms and conditions are at [https://aka.ms/corebounty](https://aka.ms/corebounty).\r
+\r
+Please do not open issues for anything you think might have a security implication.
\ No newline at end of file