Skip to content

Commit c228cd8

Browse files
Update public contact and correction routes (#2)
Route all new Project Shadow correspondence to projectshadowqa@protonmail.com while preserving exact release archives, historical signing identities, and custody evidence. Add correction, CAPA, security, research, press, collaboration, and conduct intake guidance.
1 parent 60494b2 commit c228cd8

10 files changed

Lines changed: 198 additions & 15 deletions

.github/ISSUE_TEMPLATE/config.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,11 @@
11
blank_issues_enabled: false
22
contact_links:
3+
- name: Contact, correction, or CAPA route
4+
url: https://github.com/PauseBeforeHarmProtocol/Project-Shadow/blob/main/CONTACT_AND_CORRECTIONS.md
5+
about: Use the current Project Shadow mailbox and the appropriate subject prefix.
36
- name: Private vulnerability report
47
url: https://github.com/PauseBeforeHarmProtocol/Project-Shadow/security/advisories/new
58
about: Report vulnerabilities, exploit details, secrets, or sensitive evidence privately.
69
- name: Security policy and email fallback
710
url: https://github.com/PauseBeforeHarmProtocol/Project-Shadow/security/policy
8-
about: Read the private-reporting instructions and monitored-email fallback.
11+
about: Read the private-reporting instructions and current monitored-email fallback.

CITATION.cff

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ type: software
88
authors:
99
- family-names: Linstrum
1010
given-names: Phillip
11+
email: projectshadowqa@protonmail.com
1112
version: "1.0 R1 Reference (PRELIVE)"
1213
date-released: 2026-08-14
1314
repository-code: https://github.com/PauseBeforeHarmProtocol/Project-Shadow

CODE_OF_CONDUCT.md

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,14 @@ after being directed to the private security channel are not acceptable.
2222

2323
## Reporting and response
2424

25-
For sensitive conduct reports, email
26-
`pausebeforeharmprotocol_PBHP@protonmail.com` with the subject
27-
`PROJECT SHADOW CONDUCT REPORT`. Do not place private evidence in a public
28-
issue. Maintainers may remove content, limit participation, or refer a security
29-
matter to the process in `SECURITY.md`. Decisions should be proportionate,
30-
documented where privacy permits, and open to correction when new evidence
31-
appears.
25+
For sensitive conduct reports, email `projectshadowqa@protonmail.com` with the
26+
subject prefix `[CONDUCT]`. Do not place private evidence in a public issue.
27+
Maintainers may remove content, limit participation, or refer a security matter
28+
to the process in `SECURITY.md`. Decisions should be proportionate, documented
29+
where privacy permits, and open to correction when new evidence appears.
30+
31+
The broader contact and correction policy is in
32+
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md).
3233

3334
This code governs participation only. It does not certify the project or
3435
authorize production or operational deployment.

CONTACT_AND_CORRECTIONS.md

Lines changed: 82 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,82 @@
1+
# Contact, corrections, CAPA, and security
2+
3+
**Current public contact:** `projectshadowqa@protonmail.com`
4+
**Effective:** 2026-08-17
5+
6+
Use one of these subject prefixes so the report can be routed correctly:
7+
8+
- `[CORRECTION]`
9+
- `[CAPA]`
10+
- `[SECURITY]`
11+
- `[RESEARCH]`
12+
- `[PRESS]`
13+
- `[COLLABORATION]`
14+
- `[CONDUCT]`
15+
16+
## Corrections
17+
18+
Include:
19+
20+
1. the exact page, URL, release, file, case, or claim;
21+
2. the disputed text or behavior;
22+
3. the strongest available supporting evidence;
23+
4. whether the issue is factual, interpretive, currentness-related,
24+
rights-related, technical, or procedural;
25+
5. the correction requested; and
26+
6. what evidence would verify that the correction worked.
27+
28+
## CAPA proposals
29+
30+
A useful CAPA proposal distinguishes:
31+
32+
- immediate containment;
33+
- known impact and affected stakeholders;
34+
- suspected root cause;
35+
- confirmed root cause, if available;
36+
- corrective action;
37+
- preventive action;
38+
- owner and target date, if known;
39+
- effectiveness-check method; and
40+
- evidence that would close or reopen the issue.
41+
42+
Submitting a correction or CAPA does not guarantee acceptance. Dispositions
43+
should remain evidence-bound and may be accepted, narrowed, deferred, rejected
44+
as unsupported, or closed as duplicate or out of scope with a preserved
45+
rationale.
46+
47+
## Security
48+
49+
Use `[SECURITY]` for suspected vulnerabilities, unsafe verifier behavior,
50+
secret exposure, account compromise, or sensitive technical issues. Follow
51+
[`SECURITY.md`](SECURITY.md). Do not publish exploit details, tokens, private
52+
keys, personal data, or sensitive evidence in a public issue.
53+
54+
## Privacy floor
55+
56+
Do not send:
57+
58+
- passwords, one-time codes, authenticator seeds, recovery codes, or private
59+
keys;
60+
- protected health information;
61+
- private dossiers or unnecessary personal identifiers;
62+
- confidential employer information without authority; or
63+
- real-person accusations unsupported by evidence.
64+
65+
## Historical identities and addresses
66+
67+
Older email addresses may remain inside exact-hash archives, signed records,
68+
certificates, commits, tags, quoted evidence, or other frozen historical
69+
artifacts. They are preserved for custody and verification and are **not** the
70+
current contact route.
71+
72+
In particular, a certificate identity shown in a Cosign command must match the
73+
identity recorded in the preserved signature evidence. Do not replace it with
74+
the current mailbox merely for consistency; doing so would make the
75+
verification command incorrect.
76+
77+
For all new Project Shadow correspondence, use
78+
**`projectshadowqa@protonmail.com`**.
79+
80+
This contact route does not authorize production or operational deployment and
81+
does not create efficacy, safety, certification, legal-compliance, or
82+
independent-validation claims.

CONTRIBUTING.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,17 @@ Project Shadow welcomes rigorous technical review, documentation corrections,
44
false-positive and false-negative reports, and adverse results. Outside
55
criticism is evidence to evaluate, not hostility to suppress.
66

7+
## Current contact
8+
9+
For corrections, CAPA proposals, research, press, collaboration, conduct, or a
10+
private security fallback, use `projectshadowqa@protonmail.com` with the
11+
subject prefix defined in
12+
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md).
13+
714
## Before opening a contribution
815

9-
1. Read `README.md`, `RIGHTS.md`, `SECURITY.md`, and
10-
`docs/SCOPE_AND_NONCLAIMS.md`.
16+
1. Read `README.md`, `RIGHTS.md`, `SECURITY.md`,
17+
`CONTACT_AND_CORRECTIONS.md`, and `docs/SCOPE_AND_NONCLAIMS.md`.
1118
2. Select the matching issue form before proposing a pull request.
1219
3. Use synthetic, non-sensitive evidence wherever possible.
1320
4. Report vulnerabilities privately under `SECURITY.md`; never publish exploit
@@ -20,6 +27,7 @@ criticism is evidence to evaluate, not hostility to suppress.
2027
- corrections tied to a precise path, statement, and source;
2128
- verifier mutation cases that fail closed;
2229
- false-positive, false-negative, or adverse-result reports;
30+
- correction and CAPA proposals with an effectiveness-check method;
2331
- accessibility, portability, and documentation improvements; and
2432
- narrowly scoped proposals that preserve Project Shadow's governance and
2533
nonclaim boundaries.
@@ -37,6 +45,8 @@ criticism is evidence to evaluate, not hostility to suppress.
3745
self-authorizes publication, production, or operational deployment.
3846
- Do not add efficacy, safety, certification, production-readiness, or
3947
legal-compliance claims.
48+
- Historical email addresses and certificate identities in preserved evidence
49+
must not be rewritten merely to match the current contact mailbox.
4050

4151
## Pull requests
4252

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
{
2+
"schema": "project-shadow.public-contact-status.v1",
3+
"effective_date": "2026-08-17",
4+
"current_public_contact": "projectshadowqa@protonmail.com",
5+
"subject_prefixes": [
6+
"[CORRECTION]",
7+
"[CAPA]",
8+
"[SECURITY]",
9+
"[RESEARCH]",
10+
"[PRESS]",
11+
"[COLLABORATION]",
12+
"[CONDUCT]"
13+
],
14+
"human_readable_policy": "CONTACT_AND_CORRECTIONS.md",
15+
"security_policy": "SECURITY.md",
16+
"historical_address_policy": {
17+
"preserve_exact_hash_archives": true,
18+
"preserve_signed_records_and_certificates": true,
19+
"preserve_commits_tags_and_quoted_evidence": true,
20+
"superseded_for_new_correspondence": true,
21+
"note": "Historical addresses and certificate identities remain where required for custody or cryptographic verification. They are not current correspondence routes."
22+
},
23+
"artifact_effect": {
24+
"r1_archive_modified": false,
25+
"myth_sidecar_modified": false,
26+
"release_hashes_changed": false,
27+
"admission_or_authorization_changed": false,
28+
"production_or_operational_authority_created": false
29+
},
30+
"nonclaims": {
31+
"certification_claimed": false,
32+
"efficacy_claimed": false,
33+
"independent_validation_claimed": false,
34+
"legal_compliance_claimed": false,
35+
"production_authorized": false,
36+
"operational_deployment_authorized": false,
37+
"safety_claimed": false
38+
}
39+
}

README.md

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,22 @@ governance evidence, integrity instructions, and nonclaim boundaries. It does
1515
not contain the release ZIPs in Git history; those are attached to their
1616
respective GitHub Releases.
1717

18+
## Current contact
19+
20+
All new Project Shadow correspondence should use
21+
**`projectshadowqa@protonmail.com`**.
22+
23+
Use `[CORRECTION]`, `[CAPA]`, `[SECURITY]`, `[RESEARCH]`, `[PRESS]`,
24+
`[COLLABORATION]`, or `[CONDUCT]` in the subject line. The full intake and
25+
privacy rules are in
26+
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md), with a
27+
machine-readable status in
28+
[`PUBLIC_CONTACT_STATUS_2026-08-17.json`](PUBLIC_CONTACT_STATUS_2026-08-17.json).
29+
30+
Historical addresses and certificate identities may remain inside exact-hash,
31+
signed, frozen, or quoted evidence. They are preserved for custody and
32+
verification and are not current contact routes.
33+
1834
## Exact releases
1935

2036
| Artifact | Role | Bytes | SHA-256 |
@@ -73,7 +89,8 @@ before redistribution or adaptation.
7389

7490
Technical criticism, correction evidence, false positives, false negatives,
7591
and adverse results are welcome. Outside criticism is evidence to evaluate,
76-
not hostility to suppress. Start with [`CONTRIBUTING.md`](CONTRIBUTING.md) and
77-
use the matching issue form. Report vulnerabilities privately under
92+
not hostility to suppress. Start with [`CONTRIBUTING.md`](CONTRIBUTING.md), use
93+
the matching issue form, or email `projectshadowqa@protonmail.com` with the
94+
appropriate subject prefix. Report vulnerabilities privately under
7895
[`SECURITY.md`](SECURITY.md); never place exploit details or private evidence
7996
in a public issue.

RELEASES.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,17 @@ authorized R1 or sidecar artifacts.
1919
Exact filenames, sizes, hashes, and ordering are machine-readable in
2020
[`PUBLICATION_MANIFEST.json`](PUBLICATION_MANIFEST.json).
2121

22+
## Current contact
23+
24+
For release questions, corrections, CAPA proposals, research, press,
25+
collaboration, or security routing, use `projectshadowqa@protonmail.com` with
26+
the subject prefix described in
27+
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md).
28+
29+
Historical addresses and signing identities in exact-hash archives, signed
30+
records, certificates, tags, commits, and verification commands remain
31+
preserved evidence. They are not current correspondence routes.
32+
2233
## Prospective custody procedure
2334

2435
The two 2026-08-14 tags are preserved lightweight tags pointing to the original

SECURITY.md

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,8 @@ artifact. It is not authorized for production or operational deployment.
66
For a suspected vulnerability in this repository or either exact release
77
artifact, use [GitHub private vulnerability
88
reporting](https://github.com/PauseBeforeHarmProtocol/Project-Shadow/security/advisories/new).
9-
If that private reporting surface is unavailable, email the monitored
10-
maintainer address `pausebeforeharmprotocol_PBHP@protonmail.com` with the
11-
subject `PROJECT SHADOW SECURITY REPORT`.
9+
If that private reporting surface is unavailable, email
10+
`projectshadowqa@protonmail.com` with the subject prefix `[SECURITY]`.
1211

1312
We aim to acknowledge a private report within **seven calendar days**. This is
1413
an acknowledgment target, not a promise of resolution or a statement about
@@ -27,6 +26,17 @@ Include:
2726
- expected and observed behavior; and
2827
- whether the issue reproduces after the package's embedded verifier passes.
2928

29+
Do not send passwords, one-time codes, authenticator seeds, recovery codes,
30+
private keys, protected health information, or unnecessary personal data.
31+
32+
Historical email addresses and certificate identities may remain in exact-hash
33+
archives, signed records, commits, tags, and verification commands. They are
34+
preserved evidence, not current security mailboxes. Do not replace a preserved
35+
certificate identity in a Cosign command with the current contact address.
36+
37+
The full contact, correction, and CAPA routing policy is in
38+
[`CONTACT_AND_CORRECTIONS.md`](CONTACT_AND_CORRECTIONS.md).
39+
3040
A verification pass establishes only the checks implemented by that verifier.
3141
It is not a safety, efficacy, certification, production-readiness, or
3242
legal-compliance claim.

docs/VERIFY_RELEASES.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
# Verify the exact Project Shadow releases
22

3+
For release-verification questions, corrections, or security reports, use
4+
`projectshadowqa@protonmail.com` with the appropriate subject prefix from
5+
[`CONTACT_AND_CORRECTIONS.md`](../CONTACT_AND_CORRECTIONS.md).
6+
37
Do not rely on a filename alone. Verify both byte count and SHA-256 before
48
extracting an archive.
59

@@ -107,6 +111,11 @@ Expected verification inputs:
107111
| Certificate identity | `pausebeforeharmprotocol_PBHP@protonmail.com` |
108112
| Certificate OIDC issuer | `https://github.com/login/oauth` |
109113

114+
The certificate identity in this table is the frozen historical identity
115+
recorded in the exact signature evidence. It is not the current contact
116+
mailbox. Replacing it with `projectshadowqa@protonmail.com` would make the
117+
verification command incorrect.
118+
110119
The public Rekor entry for the exact admission record is:
111120

112121
| Rekor field | Exact value |

0 commit comments

Comments
 (0)