diff --git a/README.md b/README.md
index 1820051..151b107 100644
--- a/README.md
+++ b/README.md
@@ -188,6 +188,13 @@ is for.
**Security reports are the exception** and are genuinely wanted: see
[SECURITY.md](SECURITY.md).
+## Maintenance
+
+This repository is exported from the 577i-unified monorepo by its
+`scripts/export-forge-intelligence.ts`; it is never edited directly and never
+merged back, so dependency updates arrive through the next export rather than
+through pull requests here. CI runs install + build on every PR.
+
---
diff --git a/docs/data-sources.md b/docs/data-sources.md
index a62749a..8615ab6 100644
--- a/docs/data-sources.md
+++ b/docs/data-sources.md
@@ -4,7 +4,7 @@ Every upstream feed the console consumes, with its licence and commercial
status. This file is the answer to "can we ship this?" — if a source is not
listed here, it is not wired in.
-Two rules govern the inventory, and both are load-bearing:
+Two rules govern the inventory, and both are binding:
1. **Commercial-use clean.** 577 Industries is a commercial entity, so a
source that is free only for non-commercial use is disqualified regardless
diff --git a/next.config.ts b/next.config.ts
index 44fabe3..d38396d 100644
--- a/next.config.ts
+++ b/next.config.ts
@@ -1,7 +1,7 @@
import type { NextConfig } from "next";
/**
- * Content-Security-Policy is load-bearing here, not boilerplate.
+ * Content-Security-Policy is the security boundary of this app, not boilerplate.
*
* `connect-src 'self'` is why /api/intelligence/tiles exists: the browser
* cannot reach a tile CDN directly, so the basemap is proxied through a