Public upload boundary
Package Boundary
Only the cleaned public_html/ contents are intended for web hosting.
The public upload should not include source zips, raw audit outputs, server logs, credentials, backups, deployment notes, private reports, package work folders, or local machine paths.
Visitor-facing upload, login, AI review, account creation, messaging, payment, hardware-control, and official-alert workflows are intentionally absent from this static package.
Before each upload, run the included static audit tool and inspect the generated private report. The report may document warnings that are acceptable for a static demo, but the public web root should remain clean.