Skip to content

Legal review draft

Security and Responsible Disclosure

How to report suspected UxerProof vulnerabilities safely.

Version
0.1.0-review
Status
draft
Effective
Not effective
Content hash
sha256:a9e9a7e88ccabeb6ada1ff9c4064b55b15ae92bc9b8e980e990b519c60e66ccf
Draft for legal review. This document is an accurate description of intended practice, written for engineering and product alignment. It has not yet been reviewed by counsel and is not final contractual language.

Reporting

Use the UxerProof support route and clearly label the report as a suspected security issue. Provide a safe summary, affected route or component and minimal reproduction information. Do not include credentials, raw personal data or a complete exploitable proof in ordinary support fields.

Testing boundaries

  • Test only accounts, workspaces and properties you own or are expressly authorised to test.
  • Do not access another customer's data, disrupt availability, send spam, use social engineering or retain data obtained accidentally.
  • Stop and report if testing could affect another person or production data.

No unverified commitments

No bug-bounty payment, safe-harbour term, response deadline or certification is promised by this draft. Those commitments require an approved disclosure policy and verified contact channel.

Publication blockers

This draft cannot be published until these facts are verified and approved:

  • Dedicated security contact and response commitments

Change history

  • 0.1.0-reviewdraft; not effective. Engineering-aligned draft; not published or effective.

· Privacy and data-rights requests