Skip to main content

Document metadata

Status
Maintained
Approval
Approved
Version
1.0
Classification
PUBLIC
Owner
Lightning IT Documentation Maintainers
Approver
Lightning IT Security and Compliance Maintainers
Audience
documentation contributors, security reviewers
Last reviewed
Next review
(Semiannual)

Public documentation boundary

This repository is public. Classify both filename and content before reuse, and treat uncertainty as private.

Classification outcomes

ClassificationPublic action
PUBLICMay be proposed after ordinary technical and licensing review
PUBLIC_AFTER_SANITIZATIONMay be re-authored or transformed only after independent sanitization review
PRIVATE_INTERNALDo not publish
PRIVATE_CUSTOMERDo not publish
SECRET_OR_CREDENTIALDo not publish; follow the approved secret-handling process
OBSOLETEDo not migrate as current documentation
DUPLICATEConsolidate into one public canonical topic only when the canonical source is safe
UNRESOLVEDTreat as private until resolved

Inspect more than prose

Review paths, front matter, examples, code blocks, links, diagrams, screenshots, archives, generated files, hidden files, image metadata, and history. Search for credentials, customer data, real domains and addresses, internal systems, inventory values, topology, private source locations, recovery material, support contacts, findings, accepted risks, and audit or test evidence.

Encryption or redaction markup does not automatically make a source public. An encrypted secret payload, reversible token, blurred screenshot, or hidden document property can still disclose protected information.

Safe examples

Use only explicit documentation values such as:

  • example.com and host01.example.com;
  • customer-example;
  • 192.0.2.10, 198.51.100.10, or 203.0.113.10; and
  • 2001:db8::10.

Do not invent realistic-looking Lightning IT hosts, accounts, endpoints, email addresses, or credentials.

Sanitization review

Record the original classification and checksum in the protected migration record, transform only the meaning that is safe and still useful, scan the result again, validate links and examples, and obtain a reviewer independent of the transformation. The public repository receives only the sanitized output and a safe aggregate provenance statement—not protected filenames or findings.

See the migration summary for the aggregate initial-corpus disposition.