# Instance-specific configuration
brain.yaml

# Captures and source material are private by default
inbox/*
!inbox/README.md
!inbox/.gitkeep
sources/*
!sources/README.md
!sources/.gitkeep
working/*
!working/README.md
!working/.gitkeep
!working/candidates/
working/candidates/*
!working/candidates/README.md
!working/candidates/.gitkeep
archive/*
!archive/README.md
!archive/.gitkeep

# Sensitive and local-only directories at any depth
private/
sensitive/
confidential/
restricted/
secrets/
credentials/
local-only/

# Secrets and local configuration
.env
.env.*
!.env.example
credentials.json
credentials.*.json
!credentials.example.json
!credentials.example.*.json
service-account*.json
!service-account.example*.json
secrets.*
!secrets.example.*
*.secret
*.secrets
*.pem
*.key
*.p12
*.pfx
*.kdbx
*.age
*.gpg

# Raw business exports and documents belong in ignored sources/ or approved systems
*.csv
*.tsv
*.xls
*.xlsx
*.doc
*.docx
*.pdf
*.eml
*.msg
*.vcf
*.zip
*.7z
*.tar
*.tar.gz

# Recordings and large local media
*.mp3
*.m4a
*.wav
*.mp4
*.mov

# Local databases and derived indexes
.memory/
*.db
*.sqlite
*.sqlite3
*.sqlite-*

# Common engineering source formats should remain in approved systems
*.dwg
*.dxf
*.rvt
*.shp
*.shx
*.dbf

# Python
__pycache__/
*.py[cod]
.pytest_cache/
.venv/
venv/

# Editors and operating systems
.DS_Store
Thumbs.db
.idea/
.vscode/
