docs: fix stale redaction layer counts after provider-prefix layer
main·
Commit

redact.go's detectAllLayers now runs eight regex-based layers (entropy, betterleaks pattern matching, provider token prefixes, credentialed URIs, DB connection strings, custom rules, bounded credential KV, PII), with OPF as the ninth, network-backed layer applied at push time. The security-and-privacy.md walkthrough and CLAUDE.md's OPF summary still described the pre-provider-prefix counts (five/seven/eighth); update every ordinal and layer-count reference to match the code, and add the missing "Provider token prefixes" entry to the numbered list.