Transparency is a scientific norm, not an absolute. When operational detail could materially lower the barrier to harm, responsible research requires judgment about how findings travel.
Our principle
We aim to publish enough evidence for meaningful scrutiny while withholding details that create disproportionate misuse risk. Publication decisions consider the novelty, actionability, accessibility, severity, and reversibility of potential harm—not whether a topic is uncomfortable or reputationally inconvenient.
We do not use “dual use” to hide weak methods, inconvenient findings, or ordinary criticism.
Review before release
Projects with plausible dual-use implications receive a release review separate from scientific review. The review identifies hazardous information, evaluates whether the finding changes an actor's capability, considers affected parties, and selects the least restrictive release path consistent with safety.
Factors considered
- Whether the information is already broadly and reliably available
- The expertise, resources, and time needed to operationalize it
- The magnitude and reversibility of plausible harm
- The defensive value of publication
- The readiness of mitigations and the value of coordinated action
- The likely effect of redaction, delay, or controlled access
Release tiers
Tier 1 — Open
Methods, results, and artifacts are published when misuse risk is low or the defensive and scientific value clearly dominates.
Tier 2 — Open with bounded detail
Results and methods are public, while operational parameters, prompts, code, datasets, or stepwise procedures are summarized or removed.
Tier 3 — Controlled access
Sensitive materials are shared with qualified researchers, affected organizations, or public authorities under appropriate review and handling conditions.
Tier 4 — Delayed or withheld
Release is delayed when credible harm is imminent and mitigations or coordination need time. Withholding is revisited as conditions change.
Coordinated disclosure
When we identify a vulnerability in a deployed model or system, we seek to notify the affected organization with enough detail to reproduce and mitigate it. Timelines depend on severity, active exploitation, mitigation complexity, and public interest. We reserve the option to publish when an organization is unresponsive or when continued secrecy creates greater risk.
Report a concern
For security findings or concerns about our published work, contact security@boundarysignal.org ↗. Please avoid sending sensitive biological or exploit details until a secure communication channel has been established.