# Sanitized Export

## Purpose

The working tree contains raw incident-response evidence, credentials, tokens,
cookies, and personally identifiable data. Do not share the working tree or a
plain copy of `artifacts/`, `docs/processing/`, or `findings/` externally.

Use the sanitized export workflow to create a redacted reporting bundle.

## Command

```bash
make sanitized-export
```

The command writes a timestamped bundle under `exports/sanitized/` and does not
modify source artifacts.

## Scope

The exporter includes:
- top-level project documentation;
- methodology and workflow docs;
- narrative artifacts;
- selected markdown summaries from `findings/data/`.

It excludes:
- raw evidence under `findings/`;
- archives, databases, binaries, logs, KDBX files, wallet files, and local env
  files;
- machine-scale credential datasets such as CSV/TSV extracts.

## Review Rule

The sanitized bundle is a convenience output, not a legal/compliance guarantee.
Before external sharing, manually review the generated files for residual
context that could identify victims, credentials, or active infrastructure.

