- Main Platform — production hardened
- Labs — intentionally vulnerable, strictly isolated
- Argon2id passwords
- Short-lived JWT + refresh rotation
- Zod validation everywhere
- Helmet, CORS allowlist, rate limiting, mongo-sanitize
- No plaintext secrets
- Audit logging
- Docker isolated only
- Fake/generated data
- No real credentials
- No external targeting
- No malware / persistence
- Resource limits + non-privileged
Stored as hashes only. Constant-time comparison. Rate limited.
Weighted: Auth 20%, Authz 20%, Input 15%, API 15%, DB 10%, Session 10%, Headers 5%, Logging 5%