Security corrections are accepted for the current 1.x portfolio release.
Please do not publish an exploitable finding in a public issue. Use GitHub's private vulnerability-reporting feature when enabled, or contact the repository owner through the verified contact channel on the GitHub profile. Include the affected component, reproducible steps, impact and any suggested mitigation. Do not include real credentials, customer data or confidential third-party information.
The repository demonstrates source admission, integrity verification, path containment, policy-first retrieval, access-aware evidence filtering, unsafe-query handling, data-minimised audit records, bounded request bodies, safe error envelopes and browser-security headers.
It does not provide production authentication, an enterprise policy-decision point, secrets management, TLS termination, rate limiting, durable encrypted persistence, multi-tenant isolation, hardened multi-worker serving, software-composition scanning, external penetration testing or security certification. Deployers remain responsible for those controls.
All included internal banking material is fictional. Do not submit real customer, employer or regulated data as test material.