Authentication
Passwords are hashed with bcrypt and authenticated requests use JWTs.
NexGen is being built with practical application security controls across authentication, API access, data handling, and deployment.
Passwords are hashed with bcrypt and authenticated requests use JWTs.
Database queries use parameters and user-owned resources are checked in the backend controllers.
Authentication and contact routes include rate limiting, while Helmet provides baseline HTTP security headers.
A production release still needs dynamic authorization tests, file-upload abuse tests, AI prompt-injection tests, dependency review, backup verification, monitoring, and a wired Stripe webhook flow.