Safety

Coordinated disclosure

A useful disclosure process starts before a public announcement. It needs a clear account of what was found, why it matters, who might be affected, and what information each recipient needs in order to act. This page describes the process Potomac is developing and the decisions it has not yet made.


The process

The disclosure process

For a finding that could affect deployed systems, the proposed process has four stages. The plan they produce is reassessed when evidence changes, details leak, active misuse emerges, or a mitigation proves ineffective.

  1. Validate the result

    Establish what was shown, under which assumptions, and how far it generalizes beyond the experiment. Preserve the evidence needed to investigate alternative explanations.

  2. Identify who is affected

    Find the maintainers, operators, and communities for whom the finding changes a decision, and what each of them needs to know.

  3. Coordinate

    Establish an appropriate channel, share the finding early enough for recipients to act, and prepare a mitigation and publication plan with them.

  4. Publish with limits

    Release the conclusion and the evidence that helps defenders. Withhold or delay details whose main effect would be to enable harm, with documented reasons and review points.

There may be no single vendor able to fix a cryptographic exposure. Some findings could affect many implementations or an entire network. Coordination may therefore require several technical communities and a neutral coordinator. Disagreement should be recorded and escalated rather than treated as a reason for indefinite silence or immediate release.


Timing

No universal deadline

A universal publication deadline would give false precision. The timing should reflect the finding’s reach, the practicality of mitigation, the risk of further exposure, and the value of the information to defenders. Delays should have documented reasons and review points.

This approach draws on the CERT guide to coordinated vulnerability disclosure and on NIST guidance for receiving and coordinating vulnerability reports. The final operating process must identify real owners and communication channels before the company advertises response commitments.


Publication and access

Publication and access

Different artifacts can have different consequences. An explanation of a result, a resource estimate, a reproducibility package, and an automated recovery capability should not automatically receive the same release decision. The proposed framework uses four descriptive categories.

Public research
Material assessed as suitable for broad scientific and defensive use.
Limited research access
Materials shared with approved reviewers or collaborators under defined conditions.
Coordinated disclosure
Consequential findings shared with relevant parties while mitigation and publication are prepared.
Controlled operation
Target-specific activity subject to documented authority and approved operational controls.

These categories are proposed Potomac practices, not an external certification. A release decision should record the expected scientific or defensive benefit, the misuse risk, the recipients, and the remaining uncertainty.

When details must remain restricted, public communication should still describe the conclusion and its limitations as accurately as possible. The reason for withholding material should be explainable without revealing the sensitive material itself. Restrictions should be reviewed as circumstances change.


Status

What is decided and what is not

Decided
Potomac publishes dated, sourced evidence for its contributions and separates measured results, simulations, and estimates in what it reports.
Proposed
The operating process, its owners, its communication channels, and any response commitments are proposed and will be published when they exist. Until then, use the technical contact for research enquiries and do not send private keys, seed phrases, or confidential recovery evidence through an ordinary contact link.