Audit coverage and secret handling hardened
Several audit and secret-handling gaps are closed. Changes to IP allow and deny rules are now written to the audit log — the record was previously never persisted — and enforcement is verified end to end. A blocked message now leaves a metadata-only audit record before the response returns, where a hard block previously left no trace.
The document watermark key is now a per-install managed secret rather than a value baked into the source, and can be set explicitly through configuration.
No action required.