Security & Responsible Disclosure
A public static release with no production-security certification, private vault, sensitive transaction or safe-harbour guarantee.
Public scope
The parent Site is a static public publication and browser-local reference environment. It is not a custody system, password service, payment page, production smart-contract deployment, security certification, penetration-test report, bug bounty or assurance engagement.
Do not submit secrets publicly
Do not publish vulnerabilities, private keys, seed phrases, passwords, recovery data, customer evidence, personal information or exploit-sensitive material in a public issue, repository, form or social post.
Responsible disclosure
Send a concise private report to info@quebec.ai with “SECURITY” in the subject. Include the affected URL and version, reproduction steps, observed impact and proposed mitigation. Do not access third-party data, move assets, interrupt service, persist access, extort, or disclose details before a reasonable remediation period.
Deployment responsibility
Any party deploying, forking, integrating, hosting or commercializing Materials is responsible for independent threat modelling, architecture review, dependency and supply-chain review, secrets and key governance, access control, logging, monitoring, incident response, backup, recovery, privacy, legal compliance and professional security testing.
Public/private separation
The public release must exclude private Publisher Vaults, signing material, production credentials, confidential Evidence Dockets, protected runtimes and customer secrets. A checksum or clean build proves integrity of the identified release, not absence of every vulnerability.
No universal safe harbour
This notice requests coordinated disclosure but does not create immunity, employment, agency, payment, reward or a duty to investigate or remediate. Any binding safe-harbour or bounty program must be published separately by the responsible operator.