# Security checklist
- Use HTTPS only.
- Change JWT_SECRET before launch.
- Never commit `.env` or real passwords.
- Use a strong unique cPanel database password.
- Keep Node dependencies updated.
- Limit admin accounts and use least privilege.
- Review privacy/community policies with HDC leadership.
- Prayer/pastoral information must not be treated like ordinary public posts.
- Back up the database regularly.
- Do not upload executable files through image uploads.
