11. Non‑Functional Requirements
- All public pages shall score ≥ 90 on Google Lighthouse performance and accessibility audits.
- The API shall respond to the /healthz probe in < 150 ms 95th percentile.
- All endpoints shall enforce HTTPS via HSTS with a max‑age of 31536000 s.
- Uploaded files shall be scanned by ClamAV; detections shall abort processing and log an alert.
- The server shall store all secrets in environment variables managed by a secrets manager, never in the repo.
- The system shall support horizontal scaling by keeping all session state in stateless JWTs and Redis.
- Background queues shall run idempotent jobs retried with exponential backoff up to five attempts.
No due date
0% Completed
No results
Try adjusting your search filters.