This repository is the governing control plane for the FreClean organization. It defines the production architecture, repository boundaries, release gates, security policy, and operational standards for the four active repositories.
| Repository | Production role | Must not do |
|---|---|---|
| FreClean/FreClean | Core backend, API, PostgreSQL, auth, authorization, orders, payments, compliance, audit | Bypass business rules, write database data from the frontend, or expose secrets |
| FreClean/freclean-app | Customer, staff, manager, admin, and owner application experience | Direct PostgreSQL access or authoritative business logic |
| FreClean/freclean-website | Public website, public discovery, and approved public API consumers | Direct PostgreSQL access or private core internals |
.github |
Shared governance, CI/CD, security, templates, and architecture controls | Product runtime logic |
See architecture-contract.md for the authoritative contract.
- Shared CI workflow standards for lint, typecheck, tests, build, and audit gates
- Security reporting and disclosure guidance
- Secret-scanning and repository policy enforcement
- Architecture and compatibility policy for Core/API boundaries
- Required external-review status handling for legal, tax, payment, and regulatory requirements
See CONTRIBUTING.md, CODE_OF_CONDUCT.md, and SECURITY.md for contribution and disclosure requirements.
This repository does not contain the product runtimes or production infrastructure for the other three repositories. Any runtime implementation remains in the dedicated repositories and requires their own production-ready pass before a full platform launch.