RELEASE POLICY
Make findings useful.
Keep exposure controlled.
A public report should explain a failure without turning the report into an operational guide for harm.
Report a concern
Email linh@ngo.net with a short description and an affected model or artifact identifier. Do not include secrets or live exploit details. Request a secure channel for sensitive evidence.
Evidence handling
Use synthetic identities and redact private data from traces. Restrict detailed severe-case artifacts to approved reviewers. Retain enough provenance to reproduce findings within the controlled harness.
Provider coordination
For a reproducible severe failure, contact the affected provider privately before publication. Set a case-specific timeline based on impact and remediation. Document contact attempts and unresolved risks.
Public release
Publish methodology, aggregate results, uncertainty, and safe examples. Withhold actionable dangerous procedures, private records, and reusable bypass payloads. Explain exclusions in the release manifest.
Corrections and appeals
Providers and researchers can submit counter-evidence. Preserve the original report, publish a dated correction, and identify changed labels or conditions. Funding does not confer editorial control.