Skip to main content

Liskov Marketplace Notice-and-Action Policy

Version 1.0 — effective 1 September 2026

This Policy explains how to report potentially illegal, infringing, unsafe or policy-breaching Marketplace content and how MOOSE LABS LTD trading as PROOF (PROOF) normally responds. It applies to Items and Listing Content published through the Marketplace (at the date of this Policy, all published by PROOF) and to any user submissions PROOF later accepts.

It does not replace emergency services, law-enforcement reporting, a court process or a statutory reporting route.

1. Reporting routes

Email abuse@proof.computer.

For a security vulnerability or active malicious package, use security@proof.computer and mark the report URGENT SECURITY.

For rights-owner correspondence, counter-notices, and law-enforcement or regulator requests, use legal@proof.computer.

For an immediate threat to life or safety, contact the appropriate emergency service first. For child sexual abuse material, do not download, copy or attach the material; provide the URL, identifier or hash and report it through the appropriate official channel as well as to us.

2. What can be reported

Reports may concern:

  • malware, backdoors, credential theft, hidden mining or active exploitation;
  • child sexual abuse/exploitation, terrorism or credible threats;
  • fraud, impersonation, phishing or scams;
  • copyright, trade mark, database right, patent or other IP infringement;
  • breach of an open-source licence;
  • unlawful disclosure of Personal Data, confidential information or secrets;
  • misleading listing information, hidden telemetry or undisclosed charges;
  • sanctions or export-control concerns;
  • illegal goods/services or regulated activity without authorisation;
  • ranking/review manipulation;
  • breach of the AUP or Marketplace Terms; or
  • another specific legal or safety concern.

3. Information to include

A useful notice should include:

(a) your name, organisation and reliable contact details, unless a protected/anonymous safety report is reasonably necessary;

(b) the exact Item, URL, version, publisher, listing ID, package digest, transaction hash or other locator;

(c) a clear description of the issue and why you believe it is illegal, infringing, unsafe or against policy;

(d) the country/law or right relied on where relevant;

(e) evidence you are authorised to act for a rights owner where applicable;

(f) screenshots, headers, logs, source references or safe reproduction steps where useful;

(g) whether the issue is urgent or actively exploited;

(h) the outcome you request; and

(i) a good-faith statement that the information is accurate to the best of your knowledge.

Do not include more Personal Data, illegal material, secrets or exploit code than necessary. We may ask for further information. A notice may be rejected or given lower priority if it is vague, abusive, fraudulent or impossible to locate.

4. Special information for IP notices

An IP notice should identify:

  • the protected work, mark, database or other right;
  • registration details where applicable;
  • the allegedly infringing material and exact location;
  • the legal/territorial basis of the right;
  • why an exception, licence or open-source permission does not apply;
  • the rights owner and reporter’s authority; and
  • contact details for counter-notice correspondence.

For an open-source licence report, identify the licence, relevant version/source, obligation allegedly breached and a practical cure if known.

PROOF is not a court and may not be able to determine a complex ownership or patent dispute. We may seek evidence, restrict the Item temporarily, encourage direct resolution or require a court order.

5. Triage

We prioritise reports according to likely harm, illegality, exploitability, reach and evidence. Indicative categories are:

5.1 Emergency

Examples: apparent child sexual abuse material; credible imminent threat to life; active ransomware/credential theft; live compromise affecting users; clear terrorist operational content; urgent sanctions freeze issue.

Target: immediate escalation on receipt through monitored channels and proportionate protective action as soon as reasonably practicable.

5.2 High

Examples: credible malware, material vulnerability with active exposure, widespread fraud/phishing, exposed live credentials, serious privacy breach, clear infringement affecting active downloads.

Target: initial assessment normally within one Business Day.

5.3 Standard

Examples: disputed licence, inaccurate metadata, non-urgent rights report, review manipulation, maintenance/status issue.

Target: initial assessment normally within five Business Days.

Targets are operational goals, not guaranteed resolution times. Complex legal questions, reporter delay or external investigation may take longer.

6. Actions we may take

Depending on evidence and risk, PROOF may:

  • request more information;
  • notify the Publisher and request a response or correction;
  • label a listing or warn users;
  • disable a version, deployment button, review or external link;
  • quarantine, delist or suspend an Item/account;
  • preserve a restricted evidential copy and relevant logs;
  • invalidate a Marketplace signature or integration credential;
  • notify affected customers or a relevant Network/provider;
  • restrict a country or feature;
  • refer the matter to a regulator, rights body or law-enforcement agency where lawful;
  • restore content after correction or counter-notice; or
  • decline action and explain the principal reason where appropriate.

We aim to use the least restrictive effective measure, but may act immediately without publisher notice where advance notice would increase risk, prejudice an investigation, breach law or endanger a person.

7. Publisher notice and response

In this Policy, Publisher means the person that published the affected Item. Where lawful and safe, we will tell the Publisher:

  • what content or version is affected;
  • the general nature of the report;
  • action taken or proposed;
  • information or remediation required;
  • response deadline; and
  • available appeal route.

We may withhold reporter identity, exploit detail, detection methods or legally restricted information. A Publisher must not retaliate against, threaten, dox or improperly contact a reporter.

A Publisher response should provide evidence of rights, technical explanation, remediation, updated version, corrected disclosure or a counter-notice.

8. Counter-notice and restoration

A Publisher that believes content was removed in error may submit a counter-notice identifying:

(a) the decision and Item/version;

(b) why the report or decision is mistaken;

(c) supporting licence, ownership, technical or factual evidence;

(d) remediation already completed; and

(e) a reliable contact and good-faith accuracy statement.

PROOF may share relevant parts with the original reporter where lawful. We may restore, keep restricted, request independent evidence or wait for court/regulator action. Restoration does not prevent later action on new evidence.

9. Appeals

A materially affected Publisher or User may appeal within 14 days of a decision notice. An appeal should identify a factual, legal, policy or procedural error. Significant appeals should be reviewed by a person not materially involved in the original decision where practicable.

We normally aim to decide an appeal within 10 Business Days, but urgent and complex cases may differ. Enforcement remains in place during review unless we decide it is safe to lift.

10. Repeat abuse

PROOF may restrict or terminate a person who repeatedly:

  • publishes illegal, malicious or infringing Items;
  • submits knowingly false or abusive notices;
  • evades a restriction;
  • fails to remediate serious recurring vulnerabilities;
  • manipulates ranking/reviews; or
  • retaliates against reporters.

We consider severity, frequency, knowledge, corrective action, account history and proportionality rather than applying an inflexible numerical rule in every case.

11. Reporter privacy and confidentiality

We process report information under the Liskov Privacy Notice. We may share it with the Publisher, affected users, service providers, advisers, regulators or law enforcement where necessary and lawful. Tell us if disclosure creates a safety risk; we will consider protective measures but cannot guarantee anonymity where due process or law requires disclosure.

We may preserve reports and related evidence for security, statutory duties and legal claims. Do not misuse the process to obtain confidential information or harass another person.

12. Transparency and records

PROOF keeps records of reports, severity, evidence, decisions, reasons, notices, appeals, restoration and repeat-abuse action for six years after the matter is closed, or longer where a legal claim or legal duty requires. Where law requires, PROOF may publish aggregate transparency information without exposing security-sensitive or identifying details.

13. Law-enforcement and regulator requests

Requests should be sent to legal@proof.computer from an official address and identify the legal authority, scope, deadline and contact officer. Emergency requests should be clearly marked and followed by valid process where required. PROOF may verify requests and challenge those that are unlawful, overbroad or unsafe.

14. No admission and preservation of rights

Taking or declining action is not an admission of illegality, liability or endorsement. Nothing in this Policy limits a person’s right to seek a court order, report to a regulator or use another lawful remedy.

15. Changes

PROOF may update this Policy under the Master Business Terms and will publish the version date. Urgent safety or legal changes may take effect immediately.


MOOSE LABS LTD trading as PROOF · Version 1.0 · effective 1 September 2026 · previous versions are archived by PROOF and available on request from legal@proof.computer.