GoalOS α‑AGI Ascension · Sovereign Reserve Ω
Public Institutional Edition · Sovereign Design P‑4.0

Security and Responsible Disclosure

Public research release; no production-security certification or safe-harbour promise.

Do not publish vulnerabilities, secrets, keys, recovery data, or customer information in a public issue.

Scope

The public release is a static research publication and browser-local demonstrator. It does not represent a production smart-contract deployment, custody system, wallet, settlement service, security certification, bug bounty, or assurance engagement.

Responsible disclosure

Use a private security-advisory or other confidential contact channel made available by the official repository owner. Include the affected version, file or component, reproduction steps, impact, and any proposed mitigation. Do not exploit a vulnerability beyond what is necessary to demonstrate it, access third-party data, interrupt service, move assets, or disclose details before a reasonable remediation period.

Deployment responsibility

Any party deploying, forking, integrating, hosting, or commercializing the Materials is responsible for independent threat modelling, code review, dependency review, secrets management, key governance, access control, monitoring, incident response, backup, recovery, privacy, legal compliance, and professional security testing.

No safe-harbour promise

This policy requests coordinated disclosure but does not create a universal safe harbour, immunity, reward, employment, agency, or duty to investigate, remediate, or compensate. Any separate bug-bounty or safe-harbour program must be expressly published by the responsible operator.