Application controls
Responses use a content security policy, secure session cookies, CSRF tokens, output escaping, domain validation, upstream timeouts and file-based rate limits. Production should add Cloudflare WAF rules, strict transport security, centralized logs and alerting.
Secret handling
API credentials belong in environment variables or a secret manager. They must never appear in PHP, JavaScript, Zoho, screenshots, transmission documents or client-visible JSON. All credentials pasted into the original MVP brief are considered exposed and must be rotated.
Data handling
Cached IP results use salted file names with short TTLs. Contact senders must opt in before raw connection information is attached. Resumes live outside the public directory and are disabled until private storage is approved.
Report a vulnerability
Send a concise report to [email protected] once that mailbox is operational. Do not access unrelated data, degrade service or publish a finding before coordinated remediation. A full safe-harbor policy remains a launch requirement.