Security architecture

Designed to keep the engine off the public web root.

No website can honestly be called “unhackable.” This deployment is instead structured to minimize public attack surface and keep proprietary calculations server-side.

Private engine

Calculation code outside public_html

The proprietary deck engine is stored in a sibling private directory and required only by the Node application.

Subscription gate

Authenticated member routes

The member app, project APIs and calculation endpoints require an authenticated account and active subscription entitlement.

Secrets

Environment-only credentials

Stripe keys, session secrets and engine signing secrets are loaded from a private environment file, not public JavaScript.

Abuse controls

Rate limits + CSRF + secure cookies

Login/register limits, authenticated API limits, CSRF tokens, HttpOnly cookies and same-origin requests reduce common web attack paths.

Security must also be maintained after launch: update dependencies, monitor logs, rotate secrets, back up the database and keep cPanel/Node/Stripe accounts protected with strong authentication.