Skip to content

Security

Arun Prakash N edited this page Aug 15, 2026 · 10 revisions

Canonical source: SECURITY.md · Snapshot commit: 0694e7ad548d

Security and privacy reporting

Project status

This repository contains product planning and fictional static prototypes. It does not contain a deployed service, production infrastructure, working authentication, live integrations, durable storage, or a verified backup and recovery system. There are therefore no supported production versions at this time.

Report privately

Do not open a public issue for a vulnerability, credential, real journal, real photo, personal identifier, private URL, or other sensitive material. Use GitHub's private vulnerability reporting form instead.

Include only the minimum information needed to understand and reproduce the problem. Do not attach private source content when a fictional example can demonstrate it.

Security and privacy boundaries

  • Real photos and data derived from real photos must never be sent to an AI provider.
  • Repository fixtures must remain fictional; real journal or media content does not belong in Git history, issues, discussions, workflow logs, or Wiki pages.
  • Secrets and credentials must not be committed. Local .env files are ignored, but ignore rules are not a substitute for checking changes.
  • Prototype screens and documents may describe proposed controls. They are not evidence that those controls have been implemented or verified.

If sensitive data is accidentally published, report it privately immediately so containment and history-remediation options can be evaluated before further distribution.

Life in Days

Home

Product, experience, architecture, and delivery

Discovery and research

Governance and council

Prototype handoffs

Prototype run guides

Prototype councils

QA and audits

Repository and project record

Evidence and maintenance

Clone this wiki locally