//the five controls
The five required controls, stated as practices
Direct file access prevented.
User input never composes a filesystem path. Any path is derived from a server-side identifier, resolved, and checked for containment inside its allowed root before it is opened. Uploads go to object storage through validated, size-limited streams; downloads are served as signed, short-lived links, never rendered inline.
SQL injection prevented.
All database access uses parameterised queries. String-built SQL is prohibited without exception. Sorting and filtering use a fixed set of allowed keys. An unknown key is refused, and the platform does not build a query from it.
Cross-site scripting (XSS) prevented.
Free-text is stored as plain text and escaped on output; rich text renders through a single sanitising component with an explicit allow-list of tags and attributes; a strict Content Security Policy and strict headers apply to every first-party page.
Capability and authorisation checks.
One permissions matrix declares every capability and which roles hold it. Each route declares the capability it requires, and the server checks the capability on every request. The user interface is not a security control. The interface hides what a user cannot do, and the server checks the permission again.
Secure credential storage.
Passwords are stored with PBKDF2-HMAC-SHA256 at 100,000 iterations, a per-user salt and constant-time comparison. API keys and refresh tokens are stored only as hashes, with an instantaneous revocation switch. No plaintext anywhere, ever.
The home page states the same five controls as commitments. This page is their full description, and the two pages must never disagree.