Always fun when you have to go looking for security policy docs then have a conversation the security director because your Senior SRE decided to pull scripts from his private github into a CI/CD automation pipeline...
Note the scripts weren't any bad.. but super bad procedure.
And apparently none of the docs or policy has been published yet, hence talking with SecOps director.