Security practices
Encryption in transit and at rest, least-privilege access, secrets kept out of source control, and dependency scanning in CI. Security review is part of the definition of done, not a pre-launch afterthought.
- TLS everywhere, encrypted data at rest
- Role-based access and audited credentials
- Automated dependency and secret scanning
