# Security checklist before production

- Delete `install.php` immediately after setup.
- Change/remove all demo accounts and replace the default password.
- Keep `config.php` private and never commit or share database credentials.
- Use HTTPS and secure cookies; the app sets the session cookie secure flag when HTTPS is detected.
- Add explicit CSRF tokens for state-changing requests and rate limiting for login/public quote routes before production.
- Review role permissions and implement strict record-level ownership checks for clients and assigned delivery agents.
- Store artwork and delivery media in private storage with upload limits, malware scanning and expiring links.
- Confirm payments only from authenticated M-PESA/provider callbacks and reconciled financial records. Payment screenshots are not proof of payment.
- Restrict and audit exports, refunds, invoice cancellation, permission changes and stock write-offs.
- Define privacy notices, lawful purpose, retention/deletion rules and incident procedures under applicable Kenyan data protection law.
- Configure automated database backups and regularly test restoring them.
