Collect only under explicit authorization with a reviewed scope and least-privilege access. Treat inventory, account details and network configurations as sensitive assessment evidence. Never upload real batches to public issues or CI. Retain a trusted manifest separately: matching hashes are not authentication if both content and manifest were replaced. Findings need analyst interpretation; unavailable evidence is not a secure result. Report sensitive software defects privately using the maintainer's profile contact, with synthetic data.