Design principles
The website is designed around a limited attack surface, data minimisation, encrypted transport, short log retention and controlled administrative access.
The application runs behind an Nginx reverse proxy. The public service is exposed through HTTPS, while the application listens only on the local server interface.