Security

Public security documentation should help users integrate safely without exposing implementation details that would increase operational risk.

Documentation security boundary

The public repository must not contain credentials, secrets, private keys, internal-only endpoints, private network topology, customer data, confidential incident artifacts, or deployment environment files.

Responsible publication

Security claims should be specific, verifiable, scoped to the applicable product surface, and reviewed before publication. Absence of a claim in this documentation should not be interpreted as a guarantee.

Vulnerability reporting

A dedicated public vulnerability-reporting policy will be linked here when its operational intake process is finalized.

Ask WEDNESDAY