Objective

The public repository should teach useful architecture without exposing Steve's private Chief of Staff, personal data, active authority, confidential work, or credentials.

Deterministic checks

The planned scan covers environment files, common key and token patterns, private-key headers, local home paths, private repository names, unapproved email addresses, internal network indicators, affiliate identifiers, unsupported live metrics, and unapproved binaries.

Content validation separately checks evidence labels, sources, publication state, disclosure metadata, stable slugs, and trusted local-only MDX.

Human checks

A person must review the complete diff, inspect images at full resolution, confirm licensing and attribution, assess whether a sanitized example still reveals a private system, and verify that current provider or product claims are appropriately dated.

Failure behavior

A boundary finding blocks public release. A secret exposure requires containment and credential rotation; deleting the file in a later commit is not sufficient.

Limit

No pattern list can prove that a repository contains no sensitive meaning. Deterministic scans reduce risk, while source review, contextual judgment, and owner approval remain necessary.

Evidence and limits

Sources

  1. Sam Foundry Public-Private Boundary v0.1 (primary-documentation)docs/architecture/SamFoundry-Public-Private-Boundary-v0.1.md
  2. Sam Foundry Foundation Build, Launch Plan, and Acceptance v0.1 (primary-documentation)docs/operations/SamFoundry-Foundation-Build-Launch-and-Acceptance-v0.1.md