Legal review draft
Security and Responsible Disclosure
How to report suspected UxerProof vulnerabilities safely.
- Version
- 0.1.0-review
- Status
- draft
- Effective
- Not effective
- Content hash
- sha256:a9e9a7e88ccabeb6ada1ff9c4064b55b15ae92bc9b8e980e990b519c60e66ccf
Draft for legal review. This document is an accurate description of intended practice, written for engineering and product alignment. It has not yet been reviewed by counsel and is not final contractual language.
Reporting
Use the UxerProof support route and clearly label the report as a suspected security issue. Provide a safe summary, affected route or component and minimal reproduction information. Do not include credentials, raw personal data or a complete exploitable proof in ordinary support fields.
Testing boundaries
- Test only accounts, workspaces and properties you own or are expressly authorised to test.
- Do not access another customer's data, disrupt availability, send spam, use social engineering or retain data obtained accidentally.
- Stop and report if testing could affect another person or production data.
No unverified commitments
No bug-bounty payment, safe-harbour term, response deadline or certification is promised by this draft. Those commitments require an approved disclosure policy and verified contact channel.
Publication blockers
This draft cannot be published until these facts are verified and approved:
- Dedicated security contact and response commitments
Change history
- 0.1.0-review — draft; not effective. Engineering-aligned draft; not published or effective.