diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md
new file mode 100644
index 0000000..32ba4a5
--- /dev/null
+++ b/.github/CONTRIBUTING.md
@@ -0,0 +1,110 @@
+
+
+# Contributing — ipv6-site-enforcer
+
+## Audience
+
+Developers working **on** `ipv6-site-enforcer`. For consumers (people
+calling or depending on it) see
+usage.
+
+## Local-dev setup
+
+Prerequisites — the minimum versions and where to get them:
+
+- `` v\`\\` — ``.
+
+- `` v\`\\` — ``.
+
+- GPG signing key configured (estate policy — all commits must be
+ signed). See
+ [standards/docs/secure-coding-training.md](https://github.com/hyperpolymath/standards/blob/main/docs/secure-coding-training.md).
+
+One-shot setup:
+
+``` bash
+git clone git@github.com:hyperpolymath/ipv6-site-enforcer.git
+cd ipv6-site-enforcer
+just setup # installs deps, sets up hooks
+just test # runs the full test suite
+```
+
+## Running tests
+
+- **Unit**: `just` `test-unit` — fast, no I/O.
+
+- **Integration**: `just` `test-int` — uses real services (database,
+ HTTP, etc.). Estate policy: prefer real over mocked (see
+ `feedback_integration_tests_real_db` in maintainer’s memory).
+
+- **Property**: `just` `test-prop` — randomised, slower; budget
+ documented in `docs/proof-debt.md` if applicable.
+
+- **Full**: `just` `test` — runs all of the above.
+
+## Code style
+
+We enforce style via CI (governance-reusable.yml from
+hyperpolymath/standards). Locally:
+
+``` bash
+just fmt # auto-format
+just lint # static checks
+```
+
+- All commits must be **GPG-signed** (CI enforces; see
+ [standards](https://github.com/hyperpolymath/standards)).
+
+- All source files must carry an **SPDX-License-Identifier** header (CI
+ enforces).
+
+- Conventional commits — `feat`, `fix`, `chore`, `refactor`, `docs`,
+ `test`, `ci`, `revert` (CHANGELOG is auto-generated from these via
+ [`changelog-reusable.yml`](https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml)).
+
+## Branching & PR workflow
+
+1. Branch off `main` as `claude/` (for AI agents) or
+ `/` (for humans).
+
+2. Make focused, narrow commits — one logical change per commit.
+
+3. Open a PR against `main`.
+
+4. **Enable auto-merge immediately** on every PR you open (`gh` `pr`
+ `merge` `` `--auto` `--squash`) — estate standing policy (see
+ standards#196 audit and policies).
+
+5. CI must be green. The PR auto-merges when checks pass + reviews
+ land.
+
+## Adding a new dependency
+
+1. State the **why** in the PR body — what does this dependency unlock?
+
+2. Check provenance (maintained, audited, no malicious history).
+
+3. Pin to a SHA, not a tag.
+
+4. Update `docs/architecture.adoc#Dependencies`.
+
+## Adding an ADR
+
+When you make a non-obvious design decision, write it down:
+
+1. Copy `docs/decisions/0001-template.adoc` → `0002-.adoc`.
+
+2. Fill in: Context, Decision, Consequences, Alternatives.
+
+3. Link the ADR from the README or relevant code as a comment.
+
+## Reporting issues
+
+- Bugs in `ipv6-site-enforcer`: file at
+ `hyperpolymath/ipv6-site-enforcer/issues`.
+
+- Estate-wide concerns (policy, conventions, CI): file at
+ `hyperpolymath/standards/issues`.
diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc
deleted file mode 100644
index 8559a5b..0000000
--- a/CONTRIBUTING.adoc
+++ /dev/null
@@ -1,109 +0,0 @@
-== Clone the repository
-
-git clone https://github.com/hyperpolymath/ipv6-site-enforcer.git cd
-ipv6-site-enforcer
-
-== Using Nix (recommended for reproducibility)
-
-nix develop
-
-== Or using toolbox/distrobox
-
-toolbox create ipv6-site-enforcer-dev toolbox enter
-ipv6-site-enforcer-dev # Install dependencies manually
-
-== Verify setup
-
-just check # or: cargo check / mix compile / etc. just test # Run test
-suite
-
-....
-
-### Repository Structure
-....
-
-ipv6-site-enforcer/ ├── src/ # Source code (Perimeter 1-2) ├── lib/ #
-Library code (Perimeter 1-2) ├── extensions/ # Extensions (Perimeter 2)
-├── plugins/ # Plugins (Perimeter 2) ├── tools/ # Tooling (Perimeter 2)
-├── docs/ # Documentation (Perimeter 3) │ ├── architecture/ # ADRs,
-specs (Perimeter 2) │ └── proposals/ # RFCs (Perimeter 3) ├── examples/
-# Examples (Perimeter 3) ├── spec/ # Spec tests (Perimeter 3) ├── tests/
-# Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files
-(Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├──
-ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md
-├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├──
-MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake
-(Perimeter 1) └── Justfile # Task runner (Perimeter 1)
-
-....
-
----
-
-## How to Contribute
-
-### Reporting Bugs
-
-**Before reporting**:
-1. Search existing issues
-2. Check if it's already fixed in `{{MAIN_BRANCH}}`
-3. Determine which perimeter the bug affects
-
-**When reporting**:
-
-Use the [bug report template](.github/ISSUE_TEMPLATE/bug_report.md) and include:
-
-- Clear, descriptive title
-- Environment details (OS, versions, toolchain)
-- Steps to reproduce
-- Expected vs actual behaviour
-- Logs, screenshots, or minimal reproduction
-
-### Suggesting Features
-
-**Before suggesting**:
-1. Check the [roadmap](ROADMAP.md) if available
-2. Search existing issues and discussions
-3. Consider which perimeter the feature belongs to
-
-**When suggesting**:
-
-Use the [feature request template](.github/ISSUE_TEMPLATE/feature_request.md) and include:
-
-- Problem statement (what pain point does this solve?)
-- Proposed solution
-- Alternatives considered
-- Which perimeter this affects
-
-### Your First Contribution
-
-Look for issues labelled:
-
-- [`good first issue`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/good%20first%20issue) — Simple Perimeter 3 tasks
-- [`help wanted`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/help%20wanted) — Community help needed
-- [`documentation`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/documentation) — Docs improvements
-- [`perimeter-3`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/perimeter-3) — Community sandbox scope
-
----
-
-## Development Workflow
-
-### Branch Naming
-....
-
-docs/short-description # Documentation (P3) test/what-added # Test
-additions (P3) feat/short-description # New features (P2)
-fix/issue-number-description # Bug fixes (P2) refactor/what-changed #
-Code improvements (P2) security/what-fixed # Security fixes (P1-2)
-
-....
-
-### Commit Messages
-
-We follow [Conventional Commits](https://www.conventionalcommits.org/):
-....
-
-():
-
-{empty}[optional body]
-
-{empty}[optional footer]