# Security and Data-Integrity Policy Report suspected vulnerabilities or integrity failures through a GitHub private security advisory. Do not include personal photos, full home paths, serial numbers, UUIDs, EXIF/GPS, or client data. Critical examples include source mutation, destination overwrite, false verification/backup/safe-to-remove results, cleanup of an unowned file, command injection, or a privilege expansion. High examples include ambiguous recovery, same-device backup labeled independent, forced/broad eject, socket authorization bypass, and sensitive path leakage. PhotoDock is unsandboxed same-user code. It reads a user-selected source and writes only user-selected destinations. It uses stock UDisks2/polkit, a private same-UID Unix socket, and XDG state. It has no root helper, custom policy, telemetry, cloud upload, runtime download, or remote-control API. Reproduce reports with synthetic data. Never ask a reporter to test a risky fix on irreplaceable media.