Security architecture
Designed to keep the engine off the public web root.
No website can honestly be called “unhackable.” This deployment is instead structured to minimize public attack surface and keep proprietary calculations server-side.
Private engine
Calculation code outside public_html
The proprietary deck engine is stored in a sibling private directory and required only by the Node application.
Subscription gate
Authenticated member routes
The member app, project APIs and calculation endpoints require an authenticated account and active subscription entitlement.
Secrets
Environment-only credentials
Stripe keys, session secrets and engine signing secrets are loaded from a private environment file, not public JavaScript.
Abuse controls
Rate limits + CSRF + secure cookies
Login/register limits, authenticated API limits, CSRF tokens, HttpOnly cookies and same-origin requests reduce common web attack paths.
Security must also be maintained after launch: update dependencies, monitor logs, rotate secrets, back up the database and keep cPanel/Node/Stripe accounts protected with strong authentication.