0 6 * * 60 7 * * 1-50 17 * * 50 8 * * 0• All API routes are protected by Clerk authentication
• Row-level tenant isolation enforced via tenantId on every query
• Super admin routes require SUPER_ADMIN_USER_ID env match
• Cron routes require CRON_SECRET bearer token
• Stripe webhook signatures validated via STRIPE_WEBHOOK_SECRET