# Secrets — never commit
.env
.env.*
*.env
!.env.example
!**/.env.example
*.pem
*.key
*.p12
secrets.json

# Claude
CLAUDE.md

# local scratch scripts that may hold a real credential while debugging
scratch/
*.local.sh
*.local.py

# Python
__pycache__/
*.pyc
.pytest_cache/
*.egg-info/
.venv/
venv/

# Node / Vite
node_modules/
dist/
*.local

# Verification screenshots stay local: they can show masked keys, real model
# output and test accounts, and they are evidence, not source
docs/verification/**/screenshots/

# Built packages: kept locally, never committed (docs/release-prep.md)
release-artifacts/
*.whl
*.tgz
sdk/*.tar.gz

# Local databases
*.db
*.sqlite3

# Logs & documents
*.log
logs/
*.pdf
*.docx

# Tooling / editor / OS
.claude/
.vscode/
.idea/
.DS_Store

# --- hardening pass: categories the audit found no tracked files in, but
# --- which had no rule either. Nothing was untracked to add these; they exist
# --- so a stray artefact cannot become tracked in the first place.

# Python (beyond the basics above)
.mypy_cache/
.ruff_cache/
.tox/
.coverage
.coverage.*
htmlcov/
coverage.xml
env/
ENV/

# Node / build output
build/
out/
.next/
.turbo/
.vite/
*.tsbuildinfo
npm-debug.log*
yarn-error.log*
pnpm-debug.log*
.eslintcache

# Local databases (kept alongside *.db and *.sqlite3 above)
*.sqlite
*.sqlite-journal
*.db-journal
*.sql.gz
*.dump

# Deploy-local state
.vercel/
.railway/
.netlify/

# Runtime junk
tmp/
.cache/
*.swp
*.swo
Thumbs.db

# Playwright / QA output produced by the acceptance scripts
qa_*.png
playwright-report/
test-results/