Access boundaries
Promotion customer sessions, Supabase-backed admin authentication and operational APIs use separate access paths.
Sensitive configuration
Bot tokens, service credentials, Telegram session material and encryption keys belong only in protected server configuration and must never be exposed in public clients.
Operational safeguards
The live product includes session health, permission-aware workflows, bounded workers, error handling and audit-oriented persistence where implemented.
Reporting concerns
Use the configured support channel to report suspected security issues. Do not include passwords, bot tokens or raw Telegram sessions in reports.