Reporting a security issue
Applies to: the public-draft website, the synthetic assessment preview, the published source repository, and the reference software
Status: v0.1 Public Draft
1. Where to report
Use the contact form at /contact with the intent "Report a security issue". Submissions are delivered by email to a monitored LockedIn Labs mailbox and are not published, indexed, or routed to any commercial team. The machine-readable security file at /.well-known/security.txt points to the same form and is the authoritative, dated record of the channel. Describe the affected component and the likely impact in the form; hold exploit steps and proof-of-concept material until we reply with a private route for them.
Never disclose a suspected vulnerability in a public issue, discussion, pull request, RFC, comment, or sample fixture.
2. What is in scope
- The public-draft website and the synthetic assessment preview, including their headers, content security policy, and noindex posture.
- The published reference software: the contracts package, the experimental scorer, the schemas and fixtures, and the public-site source.
- The evaluator boundary as described in the public documentation, including any way an artifact could escape its untrusted-data envelope or an evaluator could obtain score-writing authority.
3. What is out of scope
- Denial of service, load testing, or automated scanning that degrades service.
- Social engineering of LockedIn Labs staff or contributors.
- Findings that require physical access, a compromised device, or a compromised hosting-provider account.
- Reports about third-party services (for example the hosting provider or font providers) that should go to those providers directly.
- Testing against any system, account, data, or person you do not own or have explicit written authorization to assess.
4. What a useful report contains
- Affected component and commit, route, or version.
- Prerequisites and step-by-step reproduction.
- Expected and observed behavior.
- Likely impact and any data exposure.
- Proof-of-concept material with secrets and personal data removed.
- A suggested remediation if you have one, and a preferred method for secure follow-up.
5. What to expect
Response targets and public advisories begin only when the private channel and a named security owner are recorded in LIVE_VS_PLANNED.md. Until then the project makes no service-level commitment. When the program is active, the process is the one recorded in SECURITY.md: acknowledgement, protected case creation, severity assessment, containment, remediation, coordinated disclosure, and an incident review.
The project credits reporters when requested and safe to do so. It does not currently offer payment, and it does not promise legal safe harbor beyond applicable law and any written program terms published later.
