AI-Continuum must not store secrets.
- passwords
- API keys
- private keys
- recovery phrases
- tokens
- session cookies
- private documents
- raw tester feedback containing private content
If you find a secret in committed content:
- Stop using the exposed value.
- Rotate it at the source.
- Open a private maintainer report if possible.
- Do not paste the secret into an issue or PR.
The local-first tester release does not require cloud credentials. Optional cloud paths must use environment variables or ignored local env files only.
Semantic extraction, direct Graphify push, MCP write/apply graph tools, and hosted public-user mutation are blocked until separately approved.