Security is priority one. Every layer, from the first commit.
Your ledger, your customers and your payroll live here, so protection is built in and verified live, never bolted on later.
Every page, API and document link is served over TLS with HSTS. Plain HTTP only redirects.
Strict transport, no-sniff, frame denial, referrer and permissions policies, and a locked-down content policy.
Escalating per-IP lockout, per-account throttling and constant-time credential checks so accounts cannot be enumerated.
Scanners, scrapers and raw HTTP tools are refused site-wide and banned on repeat. Search and social crawlers are allowed. No bot ever reaches the admin.
Honeypot fields, minimum-fill-time tokens, rate limits, small body limits and link-spam detection on every public form and on login.
Requests for .env, .git, wp-login and similar are logged and the address is banned at the application and firewall.
Payment gateway and AI keys are encrypted server-side and never sent to the browser. Secrets are generated on the server, never shared in chat.
Daily backups with tested restores, and a liveness probe that restarts a hung process before anyone notices.
Data hosting and access
Data is hosted in secure European data centres, encrypted in transit and at rest and backed up daily. Every user gets only the permissions their role allows, every action is audited and customers reach only their own portal.
- Role-based access with eight built-in roles
- Server-side sessions, httpOnly cookies, 2FA for owners and admins
- Full audit trail of who changed what and when
- Bring your own AI key: your data never trains anyone's model

