# Security — Golden Rules ## AuthZ - Authenticate before mutating user data. - Authorize ownership: user A cannot read/write user B resources. ## Input - Validate all external input at handler boundary. - Parameterized SQL only. Never string-concatenate SQL. ## Secrets - No secrets in repo, frontend bundles, or logs. - Rotate via env / secret manager. ## Privacy - Birthday / answers / reports are personal data. - Soft-delete and future account deletion path required in design. - Log request ids; avoid logging full PII payloads. ## Content compliance - Reject generating 疗效 / 吉凶文案 in prompts and templates.