Rotate non-default JWT_SECRET in CI & prod; enforce HTTPS in prod (HSTS already set); protect main with required CI checks.