# Security and responsible testing UMoX is experimental native inference software. Treat it as untrusted until you have reviewed and reproduced the build on an isolated development machine. ## Please do not publish - Hugging Face, Qualcomm AI Hub, GitHub, MCP, or service credentials; - QAIRT/QNN SDK files or device drivers not licensed for redistribution; - customer, camera, badge-holder, access-control, or site information; - private prompts, model paths containing personal identifiers, or raw crash dumps; - compiled contexts whose license or device-binding terms are unclear. ## Genetec and MCP testing Use recorded, redacted, read-only traces or a dedicated non-production sandbox. The model must not be allowed to change real security-system state during an evaluation. Enforce allowlists, least privilege, timeouts, step limits, and a human confirmation boundary for any consequential operation. ## Reporting a vulnerability Until a private security contact is established, do not post exploitable secrets or customer data in a public Discussion. Open a minimal public report without sensitive details and ask the maintainers for a private coordination channel. This policy is an operational guideline, not a guarantee that the prototype is secure or suitable for production use.