11. Non‑Functional Requirements

  1. All public pages shall score ≥ 90 on Google Lighthouse performance and accessibility audits.
  2. The API shall respond to the /healthz probe in < 150 ms 95th percentile.
  3. All endpoints shall enforce HTTPS via HSTS with a max‑age of 31536000 s.
  4. Uploaded files shall be scanned by ClamAV; detections shall abort processing and log an alert.
  5. The server shall store all secrets in environment variables managed by a secrets manager, never in the repo.
  6. The system shall support horizontal scaling by keeping all session state in stateless JWTs and Redis.
  7. Background queues shall run idempotent jobs retried with exponential backoff up to five attempts.
No due date
0% Completed

No results

Try adjusting your search filters.