Application controls
Limit access and abusive requests
Current paths include CSRF protection, rate limits for authentication and mutations, authorization checks, and HTTPS enforcement for licensing and custom-menu domains.
Role separation
Administration, client portal, and API routes use separate authentication and authorization layers.
Audit records
Selected sensitive administrative changes are recorded without intentionally logging passwords.