diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md
new file mode 100644
index 0000000..d73b25c
--- /dev/null
+++ b/.github/PULL_REQUEST_TEMPLATE.md
@@ -0,0 +1,19 @@
+## Summary
+
+
+## Testing
+
+- [ ] Build succeeds (`go build .` from `src/`, not naming `ZeeCrypt.go` directly)
+- [ ] Encrypt → decrypt round-trip: normal mode
+- [ ] Encrypt → decrypt round-trip: paranoid mode
+- [ ] Encrypt → decrypt round-trip: keyfiles (ordered and unordered)
+- [ ] Encrypt → decrypt round-trip: deniability
+- [ ] Encrypt → decrypt round-trip: Reed-Solomon
+- [ ] Encrypt → decrypt round-trip: split/recombine
+- [ ] Wrong password on decrypt still fails as expected
+- [ ] Not applicable (docs/CI/packaging-only change)
+
+## Breaking changes
+
diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md
new file mode 100644
index 0000000..eb82402
--- /dev/null
+++ b/CODE_OF_CONDUCT.md
@@ -0,0 +1,70 @@
+# Contributor Covenant Code of Conduct
+
+## Our Pledge
+
+We as members, contributors, and leaders pledge to make participation in our
+community a harassment-free experience for everyone, regardless of age, body
+size, visible or invisible disability, ethnicity, sex characteristics, gender
+identity and expression, level of experience, education, socio-economic status,
+nationality, personal appearance, race, religion, or sexual identity
+and orientation.
+
+We pledge to act and interact in ways that contribute to an open, welcoming,
+diverse, inclusive, and healthy community.
+
+## Our Standards
+
+Examples of behavior that contributes to a positive environment for our
+community include:
+
+* Demonstrating empathy and kindness toward other people
+* Being respectful of differing opinions, viewpoints, and experiences
+* Giving and gracefully accepting constructive feedback
+* Accepting responsibility and apologizing to those affected by our mistakes,
+ and learning from the experience
+* Focusing on what is best not just for us as individuals, but for the
+ overall community
+
+Examples of unacceptable behavior include:
+
+* The use of sexualized language or imagery, and sexual attention or advances
+ of any kind
+* Trolling, insulting or derogatory comments, and personal or political attacks
+* Public or private harassment
+* Publishing others' private information, such as a physical or email
+ address, without their explicit permission
+* Other conduct which could reasonably be considered inappropriate in a
+ professional setting
+
+## Enforcement Responsibilities
+
+Project maintainers are responsible for clarifying and enforcing our standards
+of acceptable behavior and will take appropriate and fair corrective action in
+response to any behavior that they deem inappropriate, threatening, offensive,
+or harmful.
+
+## Scope
+
+This Code of Conduct applies within all community spaces (issues, pull
+requests, discussions) and also applies when an individual is officially
+representing the community in public spaces.
+
+## Enforcement
+
+Instances of abusive, harassing, or otherwise unacceptable behavior may be
+reported to the maintainer, [@TheZeekA](https://github.com/TheZeekA), by
+contacting them directly on GitHub or via a private security advisory on this
+repository. All complaints will be reviewed and investigated promptly and
+fairly.
+
+All maintainers are obligated to respect the privacy and security of the
+reporter of any incident.
+
+## Attribution
+
+This Code of Conduct is adapted from the [Contributor Covenant][homepage],
+version 2.1, available at
+[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1].
+
+[homepage]: https://www.contributor-covenant.org
+[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
new file mode 100644
index 0000000..55d9ed7
--- /dev/null
+++ b/CONTRIBUTING.md
@@ -0,0 +1,41 @@
+# Contributing to ZeeCrypt
+
+Thanks for wanting to contribute! ZeeCrypt is actively maintained and open to bug reports, feature requests, and pull requests.
+
+## Before you start
+
+- For anything beyond a small fix, consider opening an issue first to discuss the change — this avoids wasted work if the approach needs adjusting.
+- For security vulnerabilities, see [SECURITY.md](SECURITY.md) instead of opening a public issue or PR.
+- Read the [Code of Conduct](CODE_OF_CONDUCT.md).
+
+## Building from source
+
+See [src/README.md](src/README.md) for full build instructions. In short:
+```
+cd src
+go build -ldflags="-s -w -H=windowsgui -extldflags=-static" .
+```
+Note the `.` at the end rather than naming `ZeeCrypt.go` directly — Go only auto-links the `.syso` icon resource files when building the package as a whole.
+
+## Making changes
+
+This repo uses two long-lived branches:
+- **`testing`** — active development. Push feature branches and open PRs against this.
+- **`main`** — release branch. Protected: changes only land here via PR from `testing` (or a fix branch), typically once a batch of work on `testing` is ready to ship.
+
+Workflow for a change:
+1. Branch off `testing`
+2. Make your change, and if you touch the encryption/decryption code, actually build and round-trip test it (encrypt then decrypt) — normal mode, paranoid mode, keyfiles, deniability, Reed-Solomon, and split/recombine as relevant to your change. This is cryptographic software; a change that looks correct but silently breaks decryption is worse than no change at all.
+3. Open a PR into `testing`
+4. Once merged, a maintainer will fold `testing` into `main` via a separate PR when it's ready for release
+
+## Reporting bugs
+
+Please include:
+- ZeeCrypt version (shown in the window title)
+- Steps to reproduce
+- What you expected vs. what happened
+
+## Style
+
+This is a single-file Go application (`src/ZeeCrypt.go`). Match the existing style — run `gofmt` before committing. There's no test suite; changes to the cryptographic code path need to be manually verified by actually building and round-tripping real files (see above), since it can't be validated by reading the diff alone.
diff --git a/README.md b/README.md
index 6f1f12e..bb33611 100644
--- a/README.md
+++ b/README.md
@@ -2,7 +2,7 @@
ZeeCrypt is a very small, very simple, yet very secure encryption tool that you can use to protect your files. It's a Windows-only fork of [Picocrypt](https://github.com/Picocrypt/Picocrypt), designed to be the go-to tool for file encryption, with a focus on security, simplicity, and reliability. ZeeCrypt uses the secure XChaCha20 cipher and the Argon2id key derivation function to provide a high level of security.
-🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue.
+🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue. See [CONTRIBUTING.md](CONTRIBUTING.md) if you'd like to contribute code, and [SECURITY.md](SECURITY.md) to report a vulnerability.
