pre-launch security for `GroundWork`: production instances now refuse to boot with public demo credentials.
if `NODE_ENV=production` and `PSEUDONYM_SECRET` or `ADMIN_PASSWORD` are still published defaults, the app exits with a clear error. no DB touch.
demo `docker-compose.yml` now sets `GROUNDWORK_ALLOW_DEMO_DEFAULTS=1` for a warning banner instead, marking it as a DEMO stack.
security from minute zero.