Brief security policy description for use/display on github.
--- /dev/null
+# Security Policy
+
+See [docs/SECURITY-PROCESS.md](docs/SECURITY-PROCESS.md) for full details.
+
+## Reporting a Vulnerability
+
+If you have found or just suspect a security problem somewhere in curl or libcurl,
+report it on [https://hackerone.com/curl](https://hackerone.com/curl).
+
+We treat security issuse with confidentiality until disclosed controlled and responsibly.