# Security playbook

## Before public exposure
1. Replace every secret in `.env.example`; generate a long random JWT secret and a separate webhook secret.
2. Set `APP_ENV=production`; use HTTPS, disable public docs, restrict CORS, and remove/disable bootstrap after creating Owner.
3. Use separate DB credentials for migrations and runtime; never expose PostgreSQL or Redis ports publicly.
4. Enable staff TOTP/WebAuthn in a later hardened release before granting production Owner/Supervisor/Manager access.
5. Add reverse-proxy rate limiting and Cloudflare/WAF rules. Rate limits must also be enforced in the API with Redis before internet launch.
6. Store KYC documents in a private encrypted vault, issue expiring signed links, audit each access, and define retention/deletion procedures under applicable law.
7. Configure daily encrypted backups and test restoration. Redact tokens, IDs, and financial data from logs.
8. Set alerts for repeated login failures, role changes, bulk exports, ticket takeover, and payroll approval.

## Incident response
- Preserve audit logs and request IDs; do not post secrets or KYC files into incident chat.
- Revoke compromised sessions/credentials, rotate API and webhook tokens, and disable suspicious accounts.
- Snapshot relevant logs, document timeline and scope, notify privacy/legal owners when required, then perform a blameless postmortem.

## Crypto / payroll safety
No wallet private keys or custody secrets belong in this application. Use audited third-party payment providers, idempotency keys, webhook signature verification, reconciliation, and dual approval. Never mark a payout complete before provider confirmation.
