Responsible development
Security is part of the service.
The system is being designed so identity, permissions, uploaded photographs, and report history are protected at every boundary.
Never publish credentials, personal information, or exploit details in a public issue. Use the repository's private vulnerability reporting channel when available.
Access control
Authentication identifies the user, while API-enforced role permissions determine whether resident, staff, or administrative actions are allowed.
Secure data handling
Production traffic must use HTTPS. Password hashing, protected configuration, parameterised data access, and least-privilege cloud permissions are required.
Photograph safety
Uploads must be restricted by file type and size, inspected before use, stored with private permissions, and accessed through authorised, time-limited links where appropriate.
Safe development
Developers must use synthetic test data, keep secrets out of Git, review dependencies, and avoid logging tokens, private locations, or unnecessary personal information.