Security

Protected work stays behind access gates.

Public pages are intentionally narrow. Client workspaces, tenant data, billing actions, and revision history are noindex and require session validation before access.

Controls
  • CRM routes require authenticated sessions
  • Tenant misses return generic 404 responses
  • Protected routes carry noindex headers
  • Payment state changes require webhook proof
Protected by Cloudflare