--- since: 0.6.0 --- # Security Architecture ## Authentication Authentication establishes the identity of the caller. ## Authorization Authorization must be evaluated at the resource boundary: ```text authenticated user │ ▼ project membership / role │ ▼ issue/project action ``` Do not rely only on UI controls for authorization. ## Sensitive data Do not expose: - passwords/password hashes - access tokens - refresh tokens - service credentials - private integration credentials - internal stack traces ## Auditability Issue changes that materially affect workflow should be attributable to a user or service actor where the project supports audit history. ## Production controls Use: ```text HTTPS secure cookies where applicable CSRF protection where applicable rate limiting input validation least-privilege database credentials secret management outside source control ```