Developer source-handling policy
These rules apply whenever you preview, access, download, or review customer source through VerifiedCode.
Required conduct
- Use source only for this eligible VerifiedCode review.
- Do not copy source to personal storage or unapproved tools.
- Do not submit source or findings to an unapproved external AI service.
- Run untrusted code only in an approved isolated environment.
- Stop and report credentials, production data, malware, or ownership concerns.
- Remove temporary artifacts when access ends or the review closes.
- Do not contact customers outside the approved platform workflow or solicit related work directly.
Stop and escalate
Stop work and notify the security owner if you discover credentials, private keys, production or regulated data, malware, disputed ownership, or an actively exploitable critical vulnerability. Do not paste sensitive evidence into ordinary support, chat, analytics, or issue-tracking systems.
Source access is audited and may be revoked after return, reassignment, cancellation, completion, suspension, or a security hold. Claiming work records acceptance of this exact policy version.