Skip to content

Security: mcxl/audit-concierge

Security

SECURITY.md

Security And Privacy

Do not put production secrets, client evidence, audit media, or customer-identifiable working files in this repository.

This public showcase should only contain:

  • Synthetic examples.
  • Sanitized screenshots.
  • High-level architecture notes.
  • Public-facing product copy.

Before publishing changes, check for:

  • .env files or copied credentials.
  • Real client names, phone numbers, email addresses, or site addresses.
  • Raw WhatsApp exports, audit logs, recordings, photos, PDFs, spreadsheets, or report drafts.
  • Service-role keys, webhook secrets, API keys, or database URLs.

Production source and private audit data belong in the private workspace only.

There aren't any published security advisories