# Responsible disclosure boundary

A potential vulnerability—authentication bypass, exposed secret, cross-account access, insecure direct object reference or similar—does not enter the ordinary transparency receipt.

## Immediate actions

1. stop testing the affected path;
2. preserve minimal evidence without accessing additional data;
3. notify the editorial and security leads;
4. separate vulnerability evidence from ordinary project storage;
5. identify an appropriate security contact;
6. disclose confidentially with reproduction steps that do not expose third parties;
7. agree a reasonable remediation and publication process based on risk.

The laboratory does not exploit the issue, scan adjacent systems, access other users’ data or publish operational secrets.
