# Phase 1 acceptance checklist

- [ ] All SQL uses PDO prepared statements; emulated prepares are disabled.
- [ ] Login verifies `password_hash` with `password_verify` and regenerates the session ID.
- [ ] Login errors do not reveal whether an email exists; add rate limiting before production.
- [ ] POST requests validate CSRF tokens; state-changing GET routes are not present.
- [ ] Every tenant operation obtains the tenant from an authenticated membership check, not a posted tenant ID.
- [ ] Every tenant-owned SQL query includes an explicit tenant scope; add repository-level tests for this convention.
- [ ] Composite tenant-aware foreign keys are used on all business tables added in later phases.
- [ ] Audit events cover logins and sensitive business mutations; audit access is restricted.
- [ ] The web app uses a least-privilege MySQL user, not root or the schema migration account.
- [ ] HTTPS, secure session cookies, security headers, login rate limiting, backups, and restore drills are configured before launch.
- [ ] Tests verify that users in tenant A cannot read or mutate tenant B's data, including through guessed IDs.
- [ ] Secrets and real customer data are absent from source control and logs.
