Skip to content

Security: sheetgenius/bitterlog-marketing

Security

SECURITY.md

Security

Public Boundary

This repository is public marketing source. Do not commit or paste:

  • secrets, tokens, private keys, passphrases, session cookies, or credential bundles
  • customer evidence payloads, raw agent traces, prompt snapshots, stdout/stderr, rendered outputs, or private receipts
  • account delegation assertions, bearer tokens, invite tokens, or setup packets
  • ClickHouse bootstrap details, private analytics operations, or incident runbooks
  • internal DNS, billing, mailbox, provider, or support/debug material
  • generated output from .nuxt, .output, dist, test-results, or playwright-report

The public site may describe BitterLog at the product-contract level. It must not become the source for private customer evidence, live operational runbooks, or credential material.

Reporting

Report security-sensitive issues through the private Bitter support path or an approved operator contact. Do not open a public GitHub issue containing secret material, customer data, proof-of-exploit details, or reproduction artifacts that expose evidence payloads or credential state.

For public repository changes, keep reports limited to non-sensitive symptoms and move private evidence to the approved support path.

Claim Discipline

Treat custody, evidence access, and analytics availability language as security-sensitive.

Public copy can state that BitterLog preserves raw evidence with stable digests, timestamps, annotations, and account-scoped access. Public copy must not claim customer-facing raw SQL, live ClickHouse analytics, shared buyer access, or form-forwarding behavior unless the current live proof is intentionally public.

There aren't any published security advisories