Corrections & challenges
Accuracy outranks ego. Vendors, maintainers, researchers, and users can challenge any factual claim or score.
What to send
Identify the analysis URL and the specific statement or score you dispute. Include primary evidence where possible: a commit, advisory, issue, disclosure email with appropriate redactions, release note, or reproducible technical result.
What happens next
We verify the evidence, update material errors promptly, and date substantive revisions. A corrected score replaces the earlier score, while the revision note explains what changed. Good-faith vendor responses are linked from the accountability record.
Safety boundary
Do not send live private keys, seed phrases, exploit code targeting unpatched users, or personal information. Coordinate active vulnerability disclosures with the affected project first.
Email commitwatch@karma-x.io for corrections, evidence, vendor responses, or editorial questions. Never send seed phrases, private keys, or other sensitive disclosure material by ordinary email.