Current public contact: projectshadowqa@protonmail.com
Effective: 2026-08-17
Use one of these subject prefixes so the report can be routed correctly:
[CORRECTION][CAPA][SECURITY][RESEARCH][PRESS][COLLABORATION][CONDUCT]
Include:
- the exact page, URL, release, file, case, or claim;
- the disputed text or behavior;
- the strongest available supporting evidence;
- whether the issue is factual, interpretive, currentness-related, rights-related, technical, or procedural;
- the correction requested; and
- what evidence would verify that the correction worked.
A useful CAPA proposal distinguishes:
- immediate containment;
- known impact and affected stakeholders;
- suspected root cause;
- confirmed root cause, if available;
- corrective action;
- preventive action;
- owner and target date, if known;
- effectiveness-check method; and
- evidence that would close or reopen the issue.
Submitting a correction or CAPA does not guarantee acceptance. Dispositions should remain evidence-bound and may be accepted, narrowed, deferred, rejected as unsupported, or closed as duplicate or out of scope with a preserved rationale.
Use [SECURITY] for suspected vulnerabilities, unsafe verifier behavior,
secret exposure, account compromise, or sensitive technical issues. Follow
SECURITY.md. Do not publish exploit details, tokens, private
keys, personal data, or sensitive evidence in a public issue.
Do not send:
- passwords, one-time codes, authenticator seeds, recovery codes, or private keys;
- protected health information;
- private dossiers or unnecessary personal identifiers;
- confidential employer information without authority; or
- real-person accusations unsupported by evidence.
Older email addresses may remain inside exact-hash archives, signed records, certificates, commits, tags, quoted evidence, or other frozen historical artifacts. They are preserved for custody and verification and are not the current contact route.
In particular, a certificate identity shown in a Cosign command must match the identity recorded in the preserved signature evidence. Do not replace it with the current mailbox merely for consistency; doing so would make the verification command incorrect.
For all new Project Shadow correspondence, use
projectshadowqa@protonmail.com.
This contact route does not authorize production or operational deployment and does not create efficacy, safety, certification, legal-compliance, or independent-validation claims.