Skip to content

Security Boundaries

This catalog is a cross-repo reference layer, not a secrets store and not an operational control plane.

Allowed content

  • Repository identity and naming metadata
  • High-level technical function descriptions
  • Product context and lifecycle state
  • Architecture relationships at a non-sensitive level
  • Links to public or internal documentation

Disallowed content

  • Secrets, keys, tokens, passwords, or credentials
  • Sensitive production configuration values
  • Internal exploit details or attack procedures
  • Sensitive personal data
  • Detailed legal advice stored as authoritative counsel

Principle

Write enough to explain the platform clearly without turning the catalog into a risk surface.