Prelaunch security notice

Mandatory authenticator-app TOTP, verified identity, signed-token validation, secure host-only session cookies, server-side business permissions, CSRF and same-origin checks protect access. Session checks validate provider state and the recorded factor; failures deny protected access. No first visitor automatically becomes an administrator.

Secrets are configured separately from public settings. POS credentials are encrypted with a separate key. Provider refresh tokens are not retained. Backups exclude reusable authentication material from the browser format and restores quarantine access.

Security and business regression tests use isolated local data and synthetic provider responses. They do not prove deployed provider behaviour or absolute security. Real sign-in, factor removal, revocation, recovery, email delivery, remote restore and production capacity must be tested. Public security-reporting contact details are not yet published. Never include secrets or another business's information in a report.