SEC / 01Security & Trust
Report the issue without creating another one.
Use minimal, non-sensitive routing information to establish an approved exchange. Do not publish exploit details or transmit credentials, affected-user data, restricted infrastructure information, CUI, classified information, or export-controlled material through this public site.
01 / VULNERABILITY REPORTING
Establish a protected exchange first.
A dedicated public vulnerability-intake address and PGP key are not configured in this release. Do not use the disabled public contact form for vulnerability details. If you have an established Blackvalley contact, send only the minimum information needed to route the report. Existing users should continue through their established private support path.
Review contact routing02 / SAFE HANDLING
Keep the initial report sparse.
- Do not open a public issue containing exploit or infrastructure details.
- Do not transmit credentials, private keys, tokens, session material, or personal data.
- Do not test against systems or data without explicit authorization.
- Preserve evidence and timestamps; avoid unnecessary access or modification.
03 / PUBLIC SCOPE
No accreditation or compliance claim is made here.
This static public site is intentionally separated from private and mission applications. That architectural boundary does not itself establish accreditation, certification, continuous monitoring, availability, or compliance with any framework.
04 / MACHINE-READABLE POLICY
security.txt
The machine-readable file points back to this canonical policy because no dedicated public address or PGP key has been owner-configured.
Open /.well-known/security.txt