# Security Concept - Passwords use Argon2id through Passlib. - JWT access tokens are short-lived; refresh token rotation is part of the auth roadmap. - API tokens are represented as references in the current scaffold and must be encrypted before production use. - RBAC is role and permission based. - Firewall changes require preview, validation, locking, and audit records. - Proxmox write-enabled mode is explicit per cluster. - No dangerous default password should be used in production. - CORS origins are configured through environment settings. - SQL queries use SQLAlchemy ORM constructs.