INTERNAL WORKING DRAFT
Security & Open Source Policy
# FoodX Security, Misuse & Open-Source Policy — internal working draft ## Responsible disclosure Report suspected vulnerabilities privately with steps to reproduce, impact, and contact details. Do not access, alter, exfiltrate, or destroy data beyond what is needed to demonstrate the issue. ## Misuse No credential abuse, malware, denial-of-service activity, unauthorised scraping, unlawful content, evasion of safety controls, or use that violates another party’s rights. ## Open source Third-party components remain under their original licences. Maintain notices and attribution, track dependencies, review licences before distribution, and publish source or notices where a licence requires it. The final policy must add the real reporting route, security commitments, response expectations, and licence inventory.