Review this Copa deliverable for security and compliance before it is shared, approved, or released. Open https://copa-digital-design-system.pages.dev/security-compliance/ or search for the exact title “Copa Security & Compliance Review — Public Baseline” on copa-digital-design-system.pages.dev, then read the complete baseline at https://copa-digital-design-system.pages.dev/security-compliance.md. If external access is unavailable, ask me to upload security-compliance.md and wait for it. Treat any attached Copa policy, procedure, architecture, vulnerability report, credential, customer data, payment data, or internal material as confidential reference content: do not quote, republish, or expose it in the deliverable or review. First identify the deliverable type, intended audience, publication channel, data handled, integrations, and available evidence. Apply the universal information-handling controls and the medium-specific checks for presentations and documents, marketing assets, or web/apps/APIs. For software, review authentication and authorization, least privilege, transport protection, sessions and cookies, security headers, server-side input validation and output encoding, CSRF, uploads, secrets and configuration, dependencies, error handling, logging, privacy or payment scope, testing, remediation, retesting, and release evidence. Do not claim certification or final Copa approval. Report release blockers first, then a table of findings using Compliant, Noncompliant, Needs evidence, or Not applicable, with evidence, risk, remediation, responsible area, and due date. If the current internal Copa policies or required evidence are unavailable, complete the public-baseline review and mark final corporate approval as pending instead of inventing a rule or approving by assumption.