{"ok":true,"topic":"security","generatedAt":"2026-09-19T06:39:53.775Z","note":"High-level posture for auditors — not a penetration-test report.","controls":["NextAuth session cookies; public route allowlist in middleware","/book/checkout requires session","Role isolation: CUSTOMER / PROVIDER / ADMIN / FOUNDER","Stripe webhook signature verification","Rate limits on public QA + classify endpoints","Cron/agent APIs require Bearer AGENT_CRON_SECRET (demo may allow Bearer dev)","Admin/founder MFA enforced on Cloud Run by default"],"intentionalOpenWindow":["Demo open for ChatGPT/LLM QA (QA-OPEN-1)","Public /qa/* and selected /api/qa + health + classify","Demo passwords published for test accounts — lockdown later (QA-OPEN-2)"],"outOfScopeSecrets":"This endpoint never returns AUTH_SECRET, Stripe sk_, DB URLs, or webhook secrets."}