diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..5672548
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,143 @@
+
+
+# Security Policy
+
+## Reporting a Vulnerability
+
+Please do **not** report security vulnerabilities through public GitHub
+issues, discussions, or pull requests.
+
+To report a potential security vulnerability in any NVIDIA product, use one of
+the following channels:
+
+1. **NVIDIA Vulnerability Disclosure Program** (preferred):
+
+2. **Email:** [psirt@nvidia.com](mailto:psirt@nvidia.com). Please encrypt
+ sensitive reports with NVIDIA's public PGP key:
+
+3. **GitHub Private Vulnerability Reporting:** use the "Report a
+ vulnerability" button on this repository's **Security** tab, where enabled.
+
+Please include:
+
+1. Product name and version, branch, or commit that contains the
+ vulnerability.
+2. Type of vulnerability (for example code execution, denial of service,
+ buffer overflow, path traversal).
+3. Step-by-step instructions to reproduce the issue.
+4. Proof-of-concept or exploit code, if available.
+5. Potential impact, including how an attacker could exploit the issue.
+
+NVIDIA PSIRT acknowledges reports, assesses them, and coordinates fixes and
+disclosure with the reporter. OEM partners should contact their NVIDIA
+Customer Program Manager. Past bulletins are listed at
+.
+
+## Security Architecture and Context
+
+**Project:** Triton Developer Tools, a set of helper libraries and tooling
+for building applications on top of the Triton Inference Server.
+
+**Classification:** Library / SDK, plus build and development tooling. It is
+not a network service and does not open listening sockets itself.
+
+**Components:**
+
+- `server/` is a C++17 wrapper library (`TritonServer`, `InferRequest`,
+ `InferResult`, and a trace manager) over the in-process Triton Server C API
+ (`libtritonserver`), with example programs and a unit test.
+- `tools/add_copyright.py` and `.pre-commit-hooks.yaml` provide the
+ `add-license` pre-commit hook used by Triton repositories. It reads and
+ rewrites source files in the repository where it runs.
+- `server/install_dependencies_and_build.sh` installs build dependencies and
+ builds the wrapper.
+- `qa/` contains test scripts and sample Python model fixtures.
+
+**Primary security responsibility:** correct handling of caller-supplied model
+repository paths, tensor buffers, memory types, and trace file paths when
+passing them to the Triton core library, and safe, bounded file modification
+by the license hook.
+
+**Key boundaries and interfaces:**
+
+- The public C++ API in `server/include/triton/developer_tools/`.
+- Pre-commit hook invocation with file paths supplied by pre-commit.
+- Build-time package installation and downloads.
+
+**Repository Exposure Classification:** Public. Basis: the repository is
+publicly visible on GitHub.
+
+**Service Exposure Classification:** Internal-Isolated, medium confidence.
+Basis: the code is an embedded library and developer tool with no network
+listeners and no authentication surface of its own. Exposure is inherited
+from the application that embeds it.
+
+## Threat Model
+
+1. **Untrusted model repository or model content:** `TritonServer::Create`
+ accepts a model repository path from the embedding application. A
+ repository containing a malicious model or backend library can execute
+ code in the host process, because models and backends are loaded
+ in-process.
+2. **Unsafe buffer and memory handling in the tensor API:** `InferRequest`
+ and `Tensor` accept caller-provided buffers, sizes, data types, and memory
+ types (CPU, pinned, GPU). Mismatched sizes or types supplied by a caller
+ can lead to out-of-bounds reads or writes in the C++ wrapper.
+3. **Trace file path abuse:** the trace manager in `server/src/tracer.cc`
+ writes trace output to caller-supplied file paths. An attacker who
+ controls that path or its location may overwrite files or cause
+ unbounded disk usage through a high trace rate.
+4. **Unintended file modification by the license hook:**
+ `tools/add_copyright.py` rewrites files in place. Running it on untrusted
+ or unexpected paths, or through symlinks, can modify files outside the
+ intended repository.
+5. **Build-time supply chain:** `server/install_dependencies_and_build.sh`
+ adds an external package repository and signing key and installs a pinned
+ CMake version. Compromise of that source or of the build base image would
+ affect built artifacts.
+6. **Pre-commit consumers pinned by tag:** downstream repositories consume
+ the `add-license` hook by tag. Replacing or moving a tag would change code
+ executed on every contributor's machine and in CI.
+
+## Critical Security Assumptions
+
+- The embedding application is trusted and is responsible for authenticating
+ and authorizing its own users. This library provides no authentication,
+ authorization, or TLS.
+- Model repositories, backends, and shared libraries loaded by Triton come
+ from trusted sources. The library does not verify their integrity.
+- Callers validate tensor shapes, sizes, data types, and memory types before
+ passing them to the wrapper.
+- Trace file paths are chosen by the application operator and are not
+ attacker-controlled. The destination has sufficient disk space and
+ appropriate permissions.
+- The license hook runs only against files inside a trusted working tree.
+- Build environments, base images, and package mirrors used for
+ `install_dependencies_and_build.sh` are trusted.
+- Release tags are write-once and are not moved after publication.