This repository is being prepared for public release. Until a tagged release exists, treat main as active development code and verify locally before production use.
Do not publish secrets, credentials, private model paths, or exploitable details in public issues. Report security concerns privately to the repository owner or maintainer, then open a sanitized public issue only after sensitive details are removed.
Keep .env, .env.models, model weights, generated reports, packaged builds, and SQLite databases out of Git. Use .env.example as the public template and store real values only on the local machine or in a secure deployment secret store.
The repository must not distribute third-party model weights. Contributors are responsible for checking upstream model licenses and usage restrictions before using local weights under .models/.