Security model
A reverse proxy is part of the network security boundary. This page should eventually describe Refined Engine's exact trust model, supported TLS behavior, header rules, defaults, and known limitations.
Trusted upstreams
Clearly define which networks and services may be treated as trusted, especially when accepting forwarded client information.
TLS termination
Document certificate loading, protocol support, cipher policy, renewal behavior, and whether TLS is terminated by Refined Engine or an external layer.
Reporting vulnerabilities
The project includes a dedicated security.txt file and exposes it at /.well-known/security.txt. Replace the placeholder security mailbox with a monitored address before production.