Private app routes
Dashboard, project, billing, and mutation routes are protected by alpha access while production auth is hardened.
Security
MasterEngine is in private alpha. The current posture prioritizes gated app access, hosted secrets, reviewed public content, cost guardrails, and clear side-effect boundaries.
Dashboard, project, billing, and mutation routes are protected by alpha access while production auth is hardened.
Supabase, OpenAI, Stripe, admin, and cron secrets belong in hosted environment variables or untracked local env files.
Usage, billing, review, and deployment guardrails are evaluated before expensive execution.
Only reviewed public pages should be indexable. Drafts and internal tooling stay out of the sitemap.