Security and data protection overview
Resources are user-owned and protected by authentication and authorization. Session tokens and passwords must not appear in documentation, screenshots or URLs. Training preparation does not automatically ingest private chats. Public/internal documentation and retrieval have separate source classifications and server-enforced access.
Self-hosting can support deployment control; it does not establish regulatory compliance, certification, funding eligibility or organizational security readiness. Production use requires deployment-specific review, retention decisions and operational qualification. Report internal concerns through the protected feedback path rather than copying private material into public issues.