hash or metadata capture explicitly when needed.
Protect .env, database volumes, backups and collector state. Full content belongs in the authenticated inspector, not ordinary server logs. Use TLS for remote connections and keep database and private service ports inaccessible externally.
Hash chains and signatures have a limited trust model; see verification. Report vulnerabilities privately as described in the repository’s SECURITY.md. Maintenance and response times are best effort.