Skip to content

Disclosure boundary

The website cannot read a private research workspace. Publication is a deliberate declassification step, not an automatic synchronization.

A candidate record must identify the affected project, evidence, reproduction conditions, limitations, and disclosure state. Private paths, credentials, embargoed material, and unreviewed third-party data are rejected before build.

Public vulnerability work requires coordinated-disclosure authorization and two distinct approvers. Importing a sanitized bundle creates a review entry; it cannot create a published route.

Artifacts receive a stable URL and, where applicable, a checksum. A checksum proves artifact identity, not correctness.