Disclosure boundaries

Do not upload biological identifiers, credentials, raw genomic files, or other people’s information as evidence. Use minimal redacted examples.

Reporting channel

A verified public security contact has not yet been designated for this edition. No monitored mailbox or response-time commitment is implied.

Research handling

Limit testing to systems you are authorized to assess. Preserve evidence without expanding access to sensitive material.

What belongs in a useful report

A useful report identifies the affected page or function, the unexpected behavior, and the smallest safe sequence that demonstrates it. Include the approximate time and any relevant error message, but remove credentials, session identifiers, and personal or genomic information.

If demonstrating the issue would require accessing another person's data, stop before doing so. A description of the suspected boundary failure can be enough to begin a review. This page does not grant permission to test other systems or imply that a monitored reporting channel already exists; the contact limitation above still applies.

Editorial framework

Methodology · Source policy · Corrections