# Sea Haven Org Governance > Full engineering standards: [engineering-handbook](https://github.com/Sea-Haven-Industries/engineering-handbook). ## Branching and PRs - Branch prefixes: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` - PR titles: `type(scope): description (DEV-123)` — Jira key required (DEV/PLAT/SEC) - PR body sections (exact order): **Summary**, **Validation**, **Tests**, **Notes** - Route work: DEV (product), PLAT (infra/platform), SEC (security) ## Commits - Conventional Commits: `type(scope): description` - Allowed types: `feat fix docs style refactor perf test build ci chore revert release` - No AI-attribution footers ## Secrets and Security - Secrets in AWS Secrets Manager only — never in code, env vars, logs, or commits - Non-secret config in SSM Parameter Store ## CI and SHA Pins Pin every GitHub Actions ref to a full commit SHA with an inline version comment: ```yaml uses: actions/checkout@abc123def456 # v4.1.0 ``` The deterministic global pre-push security hook must not be bypassed (skipping Git hooks requires explicit approval). Linting stays in CI; do not gate on it locally.