Security and Responsible Disclosure
Public research release; no production-security certification or safe-harbour promise.
Scope
The public release is a static research publication and browser-local demonstrator. It does not represent a production smart-contract deployment, custody system, wallet, settlement service, security certification, bug bounty, or assurance engagement.
Responsible disclosure
Use a private security-advisory or other confidential contact channel made available by the official repository owner. Include the affected version, file or component, reproduction steps, impact, and any proposed mitigation. Do not exploit a vulnerability beyond what is necessary to demonstrate it, access third-party data, interrupt service, move assets, or disclose details before a reasonable remediation period.
Deployment responsibility
Any party deploying, forking, integrating, hosting, or commercializing the Materials is responsible for independent threat modelling, code review, dependency review, secrets management, key governance, access control, monitoring, incident response, backup, recovery, privacy, legal compliance, and professional security testing.
No safe-harbour promise
This policy requests coordinated disclosure but does not create a universal safe harbour, immunity, reward, employment, agency, or duty to investigate, remediate, or compensate. Any separate bug-bounty or safe-harbour program must be expressly published by the responsible operator.