Every site we build starts from the same simple engine: Visitor → Cloudflare Worker → static assets and a D1 database. No servers, no containers.
On security: salted password hashes, secure session cookies, optional sign-in with Google, optional two-factor login, rate limiting on log-ins and forms, and security headers on every page. Every version is kept, so a bad change can be rolled back.
More: The BootApp engine