Pen-test scaffold

OWASP ASVS L2 + safety mapping

A live checklist of what the next pen-test engagement (and our internal red team) should cover. Each row links to the spec under sql/ or src/lib/security.

Authentication

Authorisation

Input handling

Crypto + secrets

Abuse + safety