Governance release.

Per-team cost attribution that AWS's own bill agrees with, redaction enforced
inside the audit log rather than at its call sites, a tamper-evident hash chain
across rotated segments with an archive hook, sealed recovery of redacted values
to a key the gateway cannot read back, OIDC single sign-on, and per-team rate,
concurrency and token limits.

Also a control mapping for security review, stating what is not done as
carefully as what is.