Please open a private security advisory on GitHub for this repository.
If private advisory flow is unavailable, open an issue with minimal detail and request a private follow-up channel.
- Never commit API keys, tokens, or private keys.
- Keep local secrets in ignored environment files.
- Treat synthetic test fixtures as public; do not include real user/study data.
- Leak scan script:
./tools/ip-scan.sh - Offline smoke checks:
./tools/smoke.sh