Loventy
Security

Security notes for a static market intelligence prototype.

Current fintech pages are static. Future accounts, alerts, payments, and data APIs require separate security review.

No secrets in frontend

API keys, provider tokens, payment secrets, and backend credentials must not appear in public files.

Generated output

`site/` is generated by build and must not be staged as source.

Future review

Accounts, watchlists, alerts, payments, partners, and data feeds require threat modeling before activation.