Third-party security audit checklist and prep workflow for Spanda Control Center.
token_hash only (SPANDA_API_KEY_PEPPER set in production)SPANDA_SESSION_JWT_SECRET set when OIDC SSO is enabledSPANDA_API_REQUIRE_AUTH_READS or ingress policy when API is network-exposedSPANDA_TENANT_ID enforced on mismatched keys (403)SPANDA_SESSION_TTL_SECS)SPANDA_CONFIG_SNAPSHOT_KEY set./scripts/security_audit_prep.sh
Produces .spanda/security-audit-prep.json for auditor intake.