Isolation
PostgreSQL and Next.js remain private to the internal container network; Caddy is the only public web entry.
Security
This staging service can create test checkouts and test entitlements. It deliberately cannot accept a live event, create a real charge, or issue a production grant.
PostgreSQL and Next.js remain private to the internal container network; Caddy is the only public web entry.
Startup refuses production application mode, live billing mode, incomplete resource IDs, or a signing key that does not match the pinned wm1 test public key.
Lemon Squeezy webhooks are authenticated over the exact raw body with HMAC-SHA256 before JSON parsing, then stored and processed idempotently.
One-time codes are hashed, device activation is serialized in PostgreSQL, and no Pro entitlement can exceed two active installation records.
The Ed25519 test private key stays outside Git and build context, mounted read-only into the non-root web container only.
Structured logs omit bodies and recursively redact signatures, tokens, activation credentials, cookies, payment fields, and database secrets.
Current boundary
Responsible reports
Use the support address shown on the Support page for a suspected issue. Do not include credentials, private keys, activation tokens, mirrored media, or raw payment-provider payloads in the first report.