Choose the right reporting lane
What not to share publicly
Do not include credentials, private keys, session cookies, personal health information, regulated data, restricted datasets, private source code, private screenshots, deployment secrets, or medical/audiology advice in public GitHub issues, pull requests, comments, or email examples.
For private vulnerability email, use the subject prefix COSMOS-CQA vulnerability report and start with a minimal non-confidential summary.
Disclosure boundary: public reports should describe the surface and impact without exposing sensitive reproduction details. Private reports should begin with a minimal non-confidential summary and indicate whether details are available on request.
Maintained scope
- The static public portal at cosmos-cqa.org.
- The browser research workbench, shared packages, schemas, examples, and release artifacts.
- Public safety boundaries for optional audio sonification, visual review surfaces, local-first data handling, and claim limits.
- Repository workflows, documentation, issue templates, and deployment validation checks.
COSMOS-CQA is not a production service, clinical tool, diagnostic system, regulated workflow, or validated scientific decision system.