Security Engineering
Mandatory standards
- Protect secrets from source control and accidental disclosure
- Never commit passwords, API keys, private keys, tokens, database credentials, or production secrets
- Use least privilege for access and automation
- Review changes that affect authentication, authorization, data exposure, or execution trust carefully
- Follow PMP-001 security architecture and platform controls
- Keep environment variables, credentials, and secrets separate from source code
- Ensure logs do not expose secrets or private credentials
- The platform may provide shared security controls
- Products remain responsible for securing their own logic, data, interfaces, runtime configuration, and operational access paths
SSH and deployment access
- SSH access should be limited to approved identities and purposes
- Production deployment credentials should be protected and auditable
- AI agents must not print or copy secrets into reports, patches, or code
Recommended practices
- Minimize sensitive data stored or moved through code paths
- Log security-relevant events without revealing secrets
- Treat production access and data access as privileged operations
- Use automation to enforce security checks where practical