Do not open public issues for secrets, credential exposure, biometric data exposure, private database exposure, or access-control weaknesses.
Report security concerns directly to the project owner, Adarsh Arya, through the private contact channel associated with the repository profile.
The repository must not contain:
- API keys;
- Firebase or Google service-account keys;
.envfiles;- SQLite databases;
- generated reports;
- generated detection snapshots;
- biometric encodings, face images, or private driver data;
- private model artifacts unless intentionally distributed;
- deployment cache files.
The face biometric authentication module is archived and disconnected. It should not be re-enabled without a dedicated privacy and security review covering consent, encryption, access control, retention, and deletion.