> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nullark.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Prepare a security report

Record a reproducible Nullark security issue without exposing recovery material, signing secrets, witnesses, or a live exploit.

> **Warning:**
> Keep fund-moving bugs, recovery leaks, proof bypasses, replay bugs, and relayer-authority bugs out of public issues.

## Private contact

Nullark has not published a private reporting address yet. Keep the report offline until this page names one.

## What to record

Use a local fixture when possible. Record enough detail to reproduce the issue without running it against live funds:

```text
Title:
Affected component and source path:
Observed source revision or runtime:
Chain ID and contract, if relevant:
Preconditions:
Security invariant violated:
Impact:
Minimal reproduction:
Expected behavior:
Observed behavior:
Suggested defensive test:
Sensitive-data handling needs:
```

## Keep out of the report

- Seed phrase, private key, mnemonic, or wallet unlock signature
- Raw recovery note, recovery kit, note secret, or blinding value
- Private witness, proving intermediate, or decrypted note record
- Relayer credential, provider token, private endpoint, or deployment secret
- User-identifying data or unredacted browser storage
- Instructions that enable immediate fund movement

Never send sensitive material to an address copied from a reply, direct message, search result, or document. Wait for the verified contact published here.
