# Security Policy

## Supported Scope

This repository is public documentation for GPU benchmarking and validation methodology. It does not contain GPUValidator source code or proprietary implementation.

## Reporting a Vulnerability

Please do not open a public issue for suspected secrets, private URLs, customer identifiers, proprietary screenshots, or implementation exposure.

Use the repository owner's preferred private security contact configured in `_config.yml` or GitHub private vulnerability reporting if enabled.

## Public Disclosure Rules

Do not submit:

- Secrets, tokens, keys, private hostnames, or customer identifiers.
- GPUValidator source code, implementation details, API contracts, schemas, auth/RBAC design, agent protocols, message formats, or deployment internals.
- Production screenshots from proprietary systems.
- Benchmark metrics that are not supported by approved public evidence.

## Safe Contributions

Security-safe contributions include documentation corrections, public methodology clarifications, link fixes, typo fixes, and issue reports that avoid sensitive data.
