- HTTP hardening via
helmet - request throttling via
express-rate-limit - strict Zod input validation
- API key auth support for protected endpoints
- CORS allowlist via
ALLOWED_ORIGIN - secret scanning via
npm run security:check
- never commit real API keys, tokens, passwords, or DSNs
- keep runtime secrets in environment variables
- use
.env.exampleplaceholders only
- set strong
BUILDERBOT_API_KEY - restrict
ALLOWED_ORIGINin production - run behind TLS/reverse proxy
- run
npm run security:checkbefore pushes - rotate credentials periodically
Security posture is a first-class product feature for enterprise-grade deterministic planning APIs.