# Security

Hard rules for this product. Do not weaken them in docs examples.

## Payments

Never store a full card number or CVV. Checkout collects last four and
brand. Paystack keeps the PAN.

The Paystack webhook stays **public** and **HMAC-verified** (timing-safe
compare). Do not put it behind JWT.

## Host

Production Node listens on `127.0.0.1` only. Caddy terminates TLS on
80/443. `/api/docs` is off in production. UFW plus Lightsail networking
should allow 22 (your IP), 80, and 443 — not 4000 or 5432. Do not open
RDS to `0.0.0.0/0`.

## Auth and uploads

New upload routes require JWT. Company-scoped resources must check
membership. Do not add unauthenticated file writes.

Platform staff (`SUPER_ADMIN`, `ADMIN`, `STAFF`) manage the catalog,
people, companies, and godfather billing from `/admin`. They are not OS
operators and must not be invited into a company. OS operators (`USER`)
must not reach `/admin`.

Owner portal and tenant portal require JWT. Access is an invite row
(`OwnerPortalAccess` / `TenantPortalAccess`), not company membership.

## Catalog honesty

Do not sell a SKU that has no screen. Coming-soon catalog products stay
`COMING_SOON` with a coming-soon page. Never route those SKUs to stub
headings.

## Secrets

Do not put `PAYSTACK_SECRET_KEY` in the frontend. Do not commit `.env`
files. Local setup notes in [Shipping](../shipping/local-dev.md) list
variable **names** only. Production topology:
[Production setup](../shipping/production.md). RDS should not be open
to `0.0.0.0/0` to "enable Hyperdrive."
