Security & evidence handling
TraceNotice standard reviews are deliberately designed to minimise access and data risk.
What TraceNotice asks for
A public URL or publicly reachable interaction path, a short description of the surface, and enough non-confidential context to understand what should be reviewed.
What TraceNotice does not ask for
Passwords, session cookies, private repository access, payment credentials, private customer records, secrets, production API keys or confidential source code are outside the default public-surface workflow.
Evidence approach
Evidence is tied to the observable release state: screenshots or interaction observations, relevant copy/placement, acceptance-test notes, release references supplied by the buyer, and remediation status. The goal is a reviewer-readable record without collecting unnecessary production data.
Public intake warning
Some current intake flows use public GitHub issues. Those pages explicitly require public/non-confidential information only. If information should not be public, do not post it there; use the contact path first.
Responsible disclosure
If you identify a security issue in TraceNotice itself, use the contact path and do not include exploitable secrets or sensitive third-party data in a public issue.