01Replace sessionStorage with JWT tokensProduction must use signed JWT with expiry
02Move credentials to backend APIPasswords must never exist in frontend code — use bcrypt
03Implement refresh token rotationAccess tokens: 1hr · Refresh tokens: 7 days
04Add MFA for Clearance Level 4–5Founder & Super Admin must use TOTP (Google Authenticator)
05Server-side role enforcementAll API endpoints must validate role & clearance server-side
06IP allowlist for admin accountsFounder/Super Admin login restricted to known IP ranges
07Persistent audit log to databasePersist user_id, timestamp, action, IP — not in-memory
08Account lockout to databaseServer-side lockout after 5 failed attempts
09Rotate all demo passwords before launchEvery password in this document must change before go-live
10HTTPS onlyAll Morpheus traffic over HTTPS with HSTS headers