Report sensitive problems without publishing them
Please do not open a public issue for a suspected vulnerability, exposed file, credential, private record, or unsafe deployment condition.
Until EthicsNet publishes a dedicated private security address, use Nell Watson’s contact page and begin with “EthicsNet security report”. Include the affected URL or repository, likely impact, safe reproduction steps, and a contact route.
Research boundaries
Good-faith, non-destructive research intended to improve safety is welcome. Avoid disrupting the service, invading privacy, using social engineering, accessing other people’s data, or going beyond the minimum needed to demonstrate an issue.
Scope
This channel covers ethicsnet.org and its website repository. Linked projects may publish their own security policies, which take precedence for those projects.
Sensitive material
Do not include live credentials, personal data, or destructive proof in the first message. EthicsNet will coordinate a safer transfer method if needed.