- Documentation index and CONTRIBUTING guide
- Architecture docs: overview, crate boundaries
- API references: public REST, admin routes, gateway webhooks
- Contract docs: escrow overview, storage and events
- Development guides: setup, testing, local webhook simulation
- Operations docs: Render deploy, Docker Compose, monitoring
- Configuration and database schema references
- Security: webhook HMAC guide (complements existing security-checklist.md)
- Troubleshooting guide
- WaveFlow targets Soroban testnet by default
- GitHub webhook secret and admin API keys must be rotated before production