This repository is public marketing source. Do not commit or paste:
- secrets, tokens, private keys, passphrases, session cookies, or credential bundles
- customer evidence payloads, raw agent traces, prompt snapshots, stdout/stderr, rendered outputs, or private receipts
- account delegation assertions, bearer tokens, invite tokens, or setup packets
- ClickHouse bootstrap details, private analytics operations, or incident runbooks
- internal DNS, billing, mailbox, provider, or support/debug material
- generated output from
.nuxt,.output,dist,test-results, orplaywright-report
The public site may describe BitterLog at the product-contract level. It must not become the source for private customer evidence, live operational runbooks, or credential material.
Report security-sensitive issues through the private Bitter support path or an approved operator contact. Do not open a public GitHub issue containing secret material, customer data, proof-of-exploit details, or reproduction artifacts that expose evidence payloads or credential state.
For public repository changes, keep reports limited to non-sensitive symptoms and move private evidence to the approved support path.
Treat custody, evidence access, and analytics availability language as security-sensitive.
Public copy can state that BitterLog preserves raw evidence with stable digests, timestamps, annotations, and account-scoped access. Public copy must not claim customer-facing raw SQL, live ClickHouse analytics, shared buyer access, or form-forwarding behavior unless the current live proof is intentionally public.