See docs/security.md for full security documentation.
- No secrets committed to this repository.
- MVP uses synthetic/mock data only — no real customer data.
- No automatic purchase orders or supplier API calls.
- Connector credentials stored in
.envonly (never in DB or logs). - All recommendations require human approval before action.
- Shopify and WooCommerce connectors are disabled stubs with no live API calls.
- Scenario planning is simulated and non-mutating.
- Public releases must pass
python scripts/public_readiness_check.py.
Report security issues privately to the project maintainer. Do not open public GitHub issues for security vulnerabilities.