Security model
Security model documentation.
Security is part of the acquisition pipeline.
The intended sequence is:
text
path policy
↓
safe traversal
↓
file classification
↓
safe content acquisition
↓
credential detection
↓
redaction
↓
context generationSensitive paths
The hard-sensitive-path policy includes classes such as:
Environment files
text
.env
.env.*Credentials
text
.netrc
credentials
id_rsa
id_dsa
id_ecdsa
id_ed25519Key/certificate files
text
.key
.pem
.p12
.pfx
.crt
.cerCloud credentials
text
.aws/credentials
.config/gcloud/**
.azure/**Configured additional patterns are also supported.
Important security property
Known high-risk paths can be excluded **before content acquisition**.
This is stronger than reading the file and attempting to redact it later.
------------------------------------------------------------------------
