ProofTrail keeps a governed public surface on purpose.
The intended public documentation surface includes:
README.mdCONTRIBUTING.mdSECURITY.mdSUPPORT.mdAGENTS.md / CLAUDE.mddocs/index.mddocs/README.mddocs/architecture.mddocs/cli.mddocs/getting-started/human-first-10-min.mddocs/showcase/minimal-success-case.mddocs/reference/run-evidence-example.mddocs/reference/public-surface-policy.mddocs/reference/release-supply-chain-policy.mddocs/reference/dependencies-and-third-party.mddocs/reference/public-surface-sanitization-policy.mddocs/release/README.mddocs/assets/README.mddocs/quality-gates.mddocs/ai/agent-guide.mddocs/ai/maintainer-governance-canon.mddocs/archive/README.mddocs/localized/zh-CN/README.mdThe following must not be tracked as live public repository content:
.agents/.agent/.codex/.claude/.runtime-cache/logs/log/*.log.env files with live valuesThese directories and files are part of the non-public surface even when they exist locally for development.
Public-surface verification should include:
pnpm repo:sensitive:checkpnpm repo:sensitive:history:checkpnpm repo:pii:check./scripts/security-scan.shpnpm public:redaction:checkpnpm public:history:checknode scripts/ci/check-source-tree-runtime-residue.mjsdocs/reference/generated/governance/log-event-schema.mddocs/reference/generated/governance/runtime-output-registry.md