TLS & Network Security
Use encrypted transport and minimal public network exposure.
HTTPS
Administrative and customer web interfaces should use valid HTTPS certificates. Avoid sending authentication credentials over unencrypted HTTP.
Service exposure
Only expose services required by the deployment. Databases, Redis/cache services and private administrative endpoints should normally remain restricted from the public Internet.
Provider connections
Use TLS-enabled external provider APIs where supported and verify the intended provider endpoint before entering production credentials.
Firewall responsibility
Cloud-provider firewalls and host firewalls should reflect the actual service requirements of the deployment.