Skip to content

Security Engineering

Mandatory standards

  • Protect secrets from source control and accidental disclosure
  • Never commit passwords, API keys, private keys, tokens, database credentials, or production secrets
  • Use least privilege for access and automation
  • Review changes that affect authentication, authorization, data exposure, or execution trust carefully
  • Follow PMP-001 security architecture and platform controls
  • Keep environment variables, credentials, and secrets separate from source code
  • Ensure logs do not expose secrets or private credentials

Platform and product responsibilities

  • The platform may provide shared security controls
  • Products remain responsible for securing their own logic, data, interfaces, runtime configuration, and operational access paths

SSH and deployment access

  • SSH access should be limited to approved identities and purposes
  • Production deployment credentials should be protected and auditable
  • AI agents must not print or copy secrets into reports, patches, or code
  • Minimize sensitive data stored or moved through code paths
  • Log security-relevant events without revealing secrets
  • Treat production access and data access as privileged operations
  • Use automation to enforce security checks where practical