# Browser security boundary The browser bundle is public. Secrets, token lifecycle, raw HTML injection, dynamic code execution, untrusted script URLs, and public production source maps are prohibited defaults. `config/hosting/security-headers.json` is the declared header set. Hosting verification compares that declaration with live responses. CSP deliberately omits `unsafe-inline` and `unsafe-eval`; production code and built assets must remain compatible with that baseline. Route guards are UX hints and client validation does not replace backend authorization or validation.