Public surfaces
The public website, read-only demos, investor pages and downloadable materials must not expose command execution or private operational control.
Security
The ecosystem separates public demo surfaces from private execution, protects secrets, uses approval gates for sensitive actions and avoids exposing internal infrastructure details in public pages.

The public website, read-only demos, investor pages and downloadable materials must not expose command execution or private operational control.
Model execution, workflow execution, file operations, MCP tools, device control, customer data and server administration should require authentication, authorization and approval where appropriate.
API keys, tokens, passwords, private URLs, internal IPs and customer records must not be published in public pages, repositories or downloadable materials.
Operational changes should leave logs, selected model/node metadata, timestamps, actor identity, approval state and rollback paths when feasible.
Reasonable safeguards include least privilege, access review, environment separation, backups, encryption where appropriate, endpoint hardening and incident triage.
Security or privacy concerns may be sent to privacy@innerchispa.us. A security.txt file is included for automated discovery.