# --- Secrets ---
.env
.env.*
!.env.example
*.pem
*.key

# --- Python ---
__pycache__/
*.pyc
*.pyo
.pytest_cache/
.mypy_cache/
.ruff_cache/
.coverage
htmlcov/
*.egg-info/
.venv/
venv/
build/
dist/

# --- IDE / editor ---
.idea/
.vscode/
*.swp
*.swo

# --- OS ---
.DS_Store
Thumbs.db

# --- Bench artefacts ---
# Large per-run output payloads + judge responses can contain customer text
# even when fed public docs (the LLM sometimes echoes input in compose).
# Keep scorecard.json — that's the headline result we want versioned.
bench/runs/*/outputs/
bench/runs/*/judge_responses/

# --- HITL run artefacts ---
# Per-run human-review outputs (input + result.json + report.html). Same
# rationale as bench/runs/: large, ephemeral, may echo source text. The
# `hitl/templates/` directory and `scripts/hitl_run.py` are tracked.
hitl/runs/

# --- Internal / sensitive sources ---
# Customer transcripts and one-off extraction output never go to git.
# `data/` itself is intentionally gitignored EXCEPT for data/README.md, which
# documents the convention. See `data/README.md`.
data/*
!data/README.md
data/documents/
data/extracted/
data/outputs/
data/notes/

# --- Docker volumes / runtime ---
.redis-data/
*.log

# --- Claude Code workspace ---
# Keep checked-in: agent / command / skill definitions used by the team.
# Drop: ephemeral session state, audit transcripts, runtime locks, and
# project-local settings (which can contain editor-specific paths).
.claude/sessions/
.claude/quadruple-verify-audit/
.claude/scheduled_tasks.lock
.claude/settings.local.json
.claude/projects/

# --- public repo additions ---
# Candidate source downloads staged by prep_replacement_docs.py
data/candidates/

# Run outputs are ignored WHILE a sweep executes, so that every scorecard records
# git_dirty=false against the commit that produced it. The scorecards themselves
# are then force-added afterwards (`git add -f bench/runs/*/scorecard.json`) as
# committed evidence. Without this, arm 1's output dirties the tree for arms 2-14
# and no run in the sweep can ever claim clean provenance.
bench/runs/
