Security contact
Vulnerability reports route through RFC9116 security.txt and the public review packet.
Open security processTrust
Privacy, security, deletion receipts, and public evidence make the institution inspectable before it asks citizens to meet.
Vulnerability reports route through RFC9116 security.txt and the public review packet.
Open security processWCAG 2.2 AA is the baseline for public, onboarding, and account surfaces.
Open statementGDPR and CCPA rights are treated as product contracts, including a 24-hour deletion clause.
Open policyCitizen state is not public by default, and public profiles are architecturally denied.
A citizen can exit, receive a deletion receipt, and keep only anonymized aggregate counts behind.
Build and governance evidence is published without exposing private citizen data.