User security
- Use current MetaMask and browser software on a trusted device.
- Verify the exact URL/origin, ENS name, wallet address, chain ID, message, and legal versions.
- Never share seed phrases, private keys, recovery data, or remote-control access.
- Use a hardware wallet or appropriate organizational wallet controls for consequential assets.
- Revoke suspicious connections and investigate unexpected account/network changes.
Operator security
Before production, complete threat modelling, code/dependency review, supply-chain controls, release signing, content-hash verification, branch protection, deployment approvals, incident response, backup/pinning redundancy, privacy review, and controlled-wallet Mainnet acceptance. GitHub Pages cannot set every security header; consider an appropriate secure gateway/CDN for stricter header control.
Responsible disclosure
Report vulnerabilities privately to secretariat@montreal.ai or the official repository’s private security-advisory channel. Include release, component, reproduction, impact, and proposed mitigation. Do not exploit beyond what is necessary, access third-party data, move assets, interrupt service, or disclose details before coordinated remediation.
No certification or safe harbour
This policy is not a bug bounty, security certification, warranty, or universal legal safe harbour. Any separate program must be expressly published by the responsible operator.