Secure transport & network boundary
Everything the portal sends travels over encrypted channels with hardened browser defaults.
- HTTPS/TLS enforced for portal delivery and every API call
- Security headers (HSTS, referrer, content-type) applied by default
- Browser calls locked to a single public API base URL (CORS-scoped)
- No inbound ports or privileged listeners exposed to the customer network