Skip to content

Latest commit

 

History

History
82 lines (62 loc) · 2.64 KB

File metadata and controls

82 lines (62 loc) · 2.64 KB

Contact, corrections, CAPA, and security

Current public contact: projectshadowqa@protonmail.com
Effective: 2026-08-17

Use one of these subject prefixes so the report can be routed correctly:

  • [CORRECTION]
  • [CAPA]
  • [SECURITY]
  • [RESEARCH]
  • [PRESS]
  • [COLLABORATION]
  • [CONDUCT]

Corrections

Include:

  1. the exact page, URL, release, file, case, or claim;
  2. the disputed text or behavior;
  3. the strongest available supporting evidence;
  4. whether the issue is factual, interpretive, currentness-related, rights-related, technical, or procedural;
  5. the correction requested; and
  6. what evidence would verify that the correction worked.

CAPA proposals

A useful CAPA proposal distinguishes:

  • immediate containment;
  • known impact and affected stakeholders;
  • suspected root cause;
  • confirmed root cause, if available;
  • corrective action;
  • preventive action;
  • owner and target date, if known;
  • effectiveness-check method; and
  • evidence that would close or reopen the issue.

Submitting a correction or CAPA does not guarantee acceptance. Dispositions should remain evidence-bound and may be accepted, narrowed, deferred, rejected as unsupported, or closed as duplicate or out of scope with a preserved rationale.

Security

Use [SECURITY] for suspected vulnerabilities, unsafe verifier behavior, secret exposure, account compromise, or sensitive technical issues. Follow SECURITY.md. Do not publish exploit details, tokens, private keys, personal data, or sensitive evidence in a public issue.

Privacy floor

Do not send:

  • passwords, one-time codes, authenticator seeds, recovery codes, or private keys;
  • protected health information;
  • private dossiers or unnecessary personal identifiers;
  • confidential employer information without authority; or
  • real-person accusations unsupported by evidence.

Historical identities and addresses

Older email addresses may remain inside exact-hash archives, signed records, certificates, commits, tags, quoted evidence, or other frozen historical artifacts. They are preserved for custody and verification and are not the current contact route.

In particular, a certificate identity shown in a Cosign command must match the identity recorded in the preserved signature evidence. Do not replace it with the current mailbox merely for consistency; doing so would make the verification command incorrect.

For all new Project Shadow correspondence, use projectshadowqa@protonmail.com.

This contact route does not authorize production or operational deployment and does not create efficacy, safety, certification, legal-compliance, or independent-validation claims.