Report security issues privately to support@fluxnote.io. Include a minimal reproduction with synthetic data, affected example, and runtime versions. Do not post secrets in GitHub issues.
Never commit an actual API key or .env file. Use the minimum API scopes needed, and revoke any credential accidentally exposed. A .gitignore cannot remove information already committed to Git history.
This repository is example code, not a production credential vault. Receipts contain your prompts or scripts; keep them in an account-private directory. Run the examples only against an API origin you trust.