Security
- TLS 1.3 on public HTTPS, HSTS after verification, CAA limited to Let's Encrypt
- Admin cookies never set on the apex domain; staff 2FA required
- Stripe webhook signatures; server-side prices only
- Mail: SPF, DKIM, DMARC, MTA-STS; independent support and admin mailboxes
- Report a vulnerability to [email protected]