Handled by Tenka.cloud ACTIVE
✓TLS / HTTPS everywhere
nginx + Let's Encrypt terminate SSL and auto-renew certs; plain HTTP redirects to HTTPS.
✓Security headers preset
HSTS, X-Content-Type-Options, X-Frame-Options and Referrer-Policy set at the edge on every response.
✓Reverse-proxy isolation
nginx fronts 80/443 and proxies only to localhost:3000 — the Node process is never exposed directly.
✓IP-authenticated mail relay
Transactional email & magic-links go through an allowlisted relay — no SMTP creds in your app.
✓Metered, managed AI keys
Claude & Mistral keys are injected from the environment and billed to the VM — never committed to code.
Your app still owns DO THIS
→Validate every input
Treat all external input as untrusted: guard SQLi, XSS, SSRF, path traversal. Parameterized queries — never concatenate SQL.
→Authorize server-side, fail closed
Authentication ≠ authorization. Check permissions on every action; least privilege; an error must deny, never grant.
→Set an app-tuned CSP
The edge can't know your resources. This app ships its own Content-Security-Policy, same-origin only.
→Beat slopsquatting
Verify every dependency is real before install, pin versions, commit the lockfile. Never curl … | sh unverified.
→Guard your secrets
Load keys, tokens & passwords from the environment. Never hard-code, commit, or log them.
→Compartmentalise the code
Keep auth/session/credential code in app/auth/ and features in app/core/ so review stays contained.