Cloudflare Controls
Enable managed WAF rules, bot protection where appropriate, rate limits for auth/bid/admin/KYC endpoints and Cloudflare Access or equivalent MFA for admin areas.
Cloudflare, MFA, origin firewall, secret rotation and deployment separation controls required for production readiness.
Enable managed WAF rules, bot protection where appropriate, rate limits for auth/bid/admin/KYC endpoints and Cloudflare Access or equivalent MFA for admin areas.
Restrict origin HTTP/HTTPS to Cloudflare IP ranges and restrict SSH to approved admin IPs. Block direct public access to the app port.
Rotate JWT, DB, email/payment/KYC and SSH secrets; separate deploy user from app runtime user; keep production secrets outside the repository and release tree where possible.
Confirm ICO fee/registration status, final controller details, processor contracts and launch sign-off before real personal data is collected.
Property auction documents should be reviewed with appropriately qualified legal, financial, tax and surveying advisers before any binding decision is made.