This project is a governance reference implementation and does not require secrets in source control. Do not commit production server inventories, generated access registers, review evidence, credentials, tokens or environment-specific notification configuration.
If you identify a security issue in the code, avoid publishing production data or exploit details in a public issue.