Data minimisation
The initial contact should contain only what is needed to assess the request.
The public trust layer covers intake, privacy, retention, access, AI use, incident reporting and known limitations.
These descriptions are operational statements, not a substitute for a contract, audit report or independent certification.
The initial contact should contain only what is needed to assess the request.
Sensitive material is transferred only through an indicated channel and remains non-public.
Private applications use authenticated access and server-side persistence controls.
Hashes and action records support stability and traceability; they do not prove authorship or truth.
Retention and deletion depend on the service, contractual basis and any required hold.
Automated outputs are not treated as final decisions or autonomous forensic conclusions.
Do not include unrelated personal data or confidential evidence in an initial vulnerability report.