Current Security
- HTTP-only signed session cookies
- RBAC route gating for core APIs
- Login rate limiting + audit events
- Read-only DB enforcement
Alpha Rebuild
Legacy report logic is being ported into a containerized app with hardened auth, scoped access, and parity-driven rollout.