01

Never send credentials in the first form

Do not submit passwords, private API keys, recovery codes, full credentials, or unnecessary live customer data. An initial review needs symptoms and system names—not secrets.

02

Arrange narrow access later

After acceptance, use collaborator roles, temporary accounts, test mode, project copies, or scoped credentials. Access should be no broader or longer-lived than the approved work requires.

03

Rotate exposed secrets

If a secret appeared in browser code, a public repository, a screenshot, or chat, revoke or rotate it first. Deleting the visible copy is not enough because caches and history may retain it.

04

Request deletion or report a concern

Email help@fixaimistakes.com to request deletion of submitted project information. Report a site security concern to security@fixaimistakes.com without including an active exploit secret.