Customer and public-facing systems
- Multi-factor authentication enforced for admin accounts
- Rate limiting and lockout controls for login and recovery flows
- No exposed debug endpoints or public admin URLs
- Access controls reviewed for role escalation weaknesses