{
  "schema_version": "1.0",
  "id": "security",
  "title": "Security",
  "summary": "Source safety, credentials, and responsible disclosure.",
  "sections": {
    "source_policy": "Only public HTTPS sources are accepted; private and metadata-network destinations are blocked.",
    "credentials": "Never place API credentials in URLs or public logs.",
    "reporting": "POST /v1/support/security. Reports are rate-limited and auditable.",
    "disclosure": "Sensitive architecture, secrets, and exploit details are not returned by public Help endpoints."
  },
  "version": "2026-08-v6",
  "effective_at": "2026-08-10T00:00:00Z",
  "content_hash": "sha256:464b2f5e0a8dc6f59e1b3fd42a83ba432e3d35a5818d4f1050b0986c33207dad"
}