Legal
Security
Passwords are hashed. Sessions use Laravel's session store. Forms require a CSRF token. Chat, contact, and registration routes are rate limited.
You should still treat this as a local product demo. Use a unique password. Do not upload confidential client files unless you trust the machine running the app.
If you find a vulnerability, describe it on the contact form. Give us a chance to fix it before you publish details.