Do not open a public GitHub issue for a suspected security vulnerability or an exposed record. Report it privately to the project maintainer or the authorized Municipal ICT contact, with a description of the issue and steps to reproduce it.
- Never commit
.envfiles, passwords, API tokens, database exports, or real municipal communications. - Use fictional data only for demonstrations and screenshots.
- Keep the repository private and grant access only to approved collaborators.
- Rotate any password or token that may have been exposed immediately.
Before production use, the system must have HTTPS, a managed production database, tested backups, restricted staff access, and municipal ownership of all hosting and domain accounts.