Report sensitive defects using the maintainer's profile email; do not publish credentials or client data. The tool trusts the local OS, Python runtime and SQLite schema. Hashes compare evidence to a trusted ledger; they do not authenticate original captures or resist a writer changing both. Avoid concurrent writes during verification. HTTP structure does not prove exploitability. Secret detection is heuristic and incomplete. READY is not legal, compliance or analyst release approval.