Security

Security Practices

Version 0.3, effective 30 June 2026.

Website

Secrets

SMTP credentials, reCAPTCHA secrets, and API keys must stay in server-side configuration such as `config.local.php`; they must not be placed in public HTML or JavaScript.

Client Work

For enterprise projects, access control, logging, backup, recovery, audit, and operational support are agreed in the project architecture, DPA, and SLA.

Reporting

If you suspect a security issue or impersonation attempt, use the contact form and include only non-sensitive details.