Fractal Framework runs locally and can hold API keys, browser-authentication state, research material, and unpublished campaign work. Keep .env, wizard/data/, bridge outputs, and NotebookLM browser state out of version control.
If you discover a vulnerability, report it privately through GitHub's security-advisory feature. Include the affected component, reproduction steps, and likely impact. Do not open a public issue containing credentials, authentication artifacts, private campaign data, or an active exploit.