- Never commit Razorpay key secrets or LLM API keys.
- Use Razorpay Test Mode for this project demo.
- Keep
.envlocal; commit only.env.example. - PayPilot is intentionally read-only and does not execute financial actions.
- Treat anomaly results as investigation signals, not fraud verdicts.