A living record

Corrections & challenges

Accuracy outranks ego. Vendors, maintainers, researchers, and users can challenge any factual claim or score.

What to send

Identify the analysis URL and the specific statement or score you dispute. Include primary evidence where possible: a commit, advisory, issue, disclosure email with appropriate redactions, release note, or reproducible technical result.

What happens next

We verify the evidence, update material errors promptly, and date substantive revisions. A corrected score replaces the earlier score, while the revision note explains what changed. Good-faith vendor responses are linked from the accountability record.

Safety boundary

Do not send live private keys, seed phrases, exploit code targeting unpatched users, or personal information. Coordinate active vulnerability disclosures with the affected project first.

Contact channel

Email commitwatch@karma-x.io for corrections, evidence, vendor responses, or editorial questions. Never send seed phrases, private keys, or other sensitive disclosure material by ordinary email.