# Patterns that must never appear in the public export (grep -E, one per line, # comments ignored). # This is the committed, non-secret subset of the public mirror's identity list (igneum-public/tools/identity.local, # which stays private because its remaining entries would themselves name what must stay out). Machine names, LAN # and overlay addresses, home paths, local time zones and the log-intake key pattern. Never a key, never a name. # Checked by tools/ci/identity-check.sh over the export list of igneum-public/tools/sync.sh after its generic scrub. # Not forbidden (decision of 5 October 2026): the registered address of Igneum Labs LTD, Innovation One, Dubai International # Financial Centre (DIFC). It is the one location that may appear in public text. The founder and the earlier entity stay in # the private list. DESKTOP-[A-Z0-9]{7} MacBook 192\.168\. 100\.[0-9]+\.[0-9]+\.[0-9]+ \+0100 \bBST\b /Users/ C:\\Users ~/Desktop log-intake LOG_INTAKE intake[_-]?key Tailscale tailscale ts\.net # 6 October 2026, the public ledger page leak (site audit): the two Windows machines are described, never numbered. The # audit's other patterns (config paths, process ids, listen addresses, --rpclisten=) live in site/forbidden-strings.txt: # they are for the served pages, and the public export carries simulator schedule logs where a pid is a pid. (The block # had been appended as one line with literal \n text, so none of it was active until the evening of 6 October 2026.) \bPC [12]\b