Skip to content

Contributing Safely

David Condrey edited this page Aug 8, 2026 · 1 revision

Contributing safely

Before proposing a field, metric, provider integration, identity workflow, or moderation rule, explain:

  • who benefits and who could be harmed;
  • what is collected, where it is stored, who can see it, and when it is deleted;
  • how a person declines, corrects, withdraws, appeals, or restores access;
  • what happens when the system is wrong, unavailable, compromised, or abused; and
  • how the change will be tested with lived-experience participants, low-cost devices, and assistive tech.

Use synthetic fixtures. Never commit real client data, names, DOBs, ZIPs, recovery cards, credentials, private keys, or screenshots containing protected information. For a security vulnerability, use the private security-reporting process rather than a public discussion.

Clone this wiki locally