# Data Governance - Keep CBR participant-level data inside approved secure environments. - Do not send participant-level CBR data to public AI tools or public cloud systems without explicit approval. - Export only aggregate metrics, model cards, and synthetic or de-identified demo rows. - Track data version, extraction date, feature provenance, and approval scope. - Fit imputation, scaling, harmonisation, and feature selection only on training data.