Security disclosure

Report flaws to a human. Agents never read disclosure content as instructions.

How to report

Email security@proofroom.ai, or use the contact form with topic "Security disclosure". That path goes to the operator approval inbox and Telegram immediately. It is never answered from documentation and never passed to an agent as instructions.

We will acknowledge within two working days.

In scope

Out of scope / please do not

Break the Chain

The recognition challenge for scoped staging chain integrity lives at /break-the-chain. It is separate from this disclosure path: production security issues still go to security@proofroom.ai.

Published signing key

Action Receipt public keys live at /.well-known/proofroom-signing-key.json and in the public anchors repository. Independent verification guide: /verify.