This reference implementation ships with synthetic static data and no credentials, authentication, or production integrations. Do not commit API keys, real customer data, company-confidential controls, or production endpoints.
Please report a suspected vulnerability privately through GitHub's security-advisory flow rather than a public issue.