This repository contains static Markdown documentation only — personal study notes, case-study reflections, and framework summaries. It does not contain deployable code, scripts, infrastructure, credentials, or executable content of any kind. As a result, there is no "attack surface" in the traditional sense, but the policy below covers content-accuracy and privacy concerns, which are the realistic risk categories for a repository like this.
If you find any of the following in this repository, please open an issue (or contact the repository owner directly if you're not comfortable opening a public issue):
- Factual inaccuracies in a case study or framework note, especially anything that misrepresents a cited source.
- A broken or misleading external link.
- Any real, identifiable personal data that should not be here — this repository is intended to contain zero real personal data about any third party, and any instance found should be reported and will be removed immediately.
- Content that reads as operational/offensive material (e.g., something that could function as attack instructions rather than defensive/educational analysis) — this repository is intended to be strictly defensive and educational, and any drift from that standard is a bug to be fixed.
- A fabricated or unverifiable citation. Every factual claim about a real incident should trace to a real, linked source; if one doesn't, please flag it.
- No credentials, API keys, tokens, or secrets of any kind.
- No exploit code, malware samples, or working offensive tooling.
- No real, non-public organization's internal security details.
- No real third-party personal data.
As this is a personal learning-portfolio repository, there is no formal SLA, but content-accuracy or privacy reports will be prioritized and addressed promptly.