# Security and Responsible Disclosure

Report a suspected security issue affecting this static framework website or publicly described UCE verification materials to help@cbyuce.com with the subject line `[Security] UCE Framework Report`.

In the initial report:

- describe the affected public URL or artifact and the observed behavior;
- provide minimal, non-destructive reproduction steps;
- do not include private keys, credentials, wallet files, production settings, private user data, or an exploit that exposes third-party data; and
- do not modify, delete, or publicly disclose another person's evidence or account data.

This contact channel is not a bug-bounty program, guaranteed response-time commitment, external audit, or certification. Operational CbyUCE service activity is governed by the policies published at https://cbyuce.com/terms and https://cbyuce.com/privacy.
