This repository primarily contains marketing, grants, outreach, and ecosystem materials rather than production runtime code.
Use a private security-reporting channel on the relevant canonical engineering repository whenever possible. Do not publish credentials, private keys, operator/customer PII, exploitable vulnerabilities, or private partner data in a public issue.
Security-sensitive technical findings should be reported to the repository that contains the implementation, for example:
pq-rdl-blockchainqmoosa-deep-tech-ai-quantum-platformqmoosa-nexus-platformqtonQSui
Never commit:
- API tokens or cloud credentials
- seed phrases or wallet private keys
- personal contact lists
- unpublished customer/operator data
- private grant or partner credentials
- secrets copied from third-party services
If a security, audit, certification, deployment, compliance, or cryptographic claim is inaccurate, treat that as a documentation defect and correct it promptly.