diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000000000000000000000000000000000000..e28984b0355a2cb6164150b79d0a11407966fbfa
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,12 @@
+# Security Policy
+
+## Supported Versions
+
+We only make security updates to the latest MAJOR.MINOR version of the project. No securit updates are backported to previous versions. If you
+want be up to date on security patches, make sure your Plausible image is up to date with `plausible/analytics:latest`
+
+## Reporting a Vulnerability
+
+If you've found a security vulnerability with the Plausible codebase, you can disclose it responsibly by sending a summary to security@plausible.io.
+We will review the potential threat and fix it as fast as we can. We are incredibly thankful for people who disclose vulnerabilities, unfortunately we do not
+have a bounty program in place yet.