Security

Assume leaked credentials are compromised.

Report safely

Use the verified private business channel. Do not open a public issue containing exploit details, tokens, client paths, cloud IDs, or evidence.

Contain first

Revoke and rotate exposed credentials, stop further publication, preserve audit evidence, and then repair history or caches as required.

Minimum controls

Least privilege, environment-only secrets, immutable source evidence, one-writer locking, hash manifests, CI scans, and human release gates.

Public/private split

Public code and synthetic examples stay separate from client manifests, reports, exact legal descriptions, Drive identifiers, and job results.