Security

Uploaded files are encrypted before storage and are never placed in the public document root. Signer links use random tokens stored only as hashes. Sessions, CSRF protection, rate limits, and role checks protect account and admin workflows.