Built-in capabilities
The runtime supports privacy-minimized first-party events, protected contact intake, owner Google OAuth sessions, and merchant checkout through Stripe, PayPal, or Creem. A requirement outside this runtime remains blocked until a concrete backend delivery contract exists.
Origin and abuse controls
Runtime APIs reject unknown Origins. Contact intake uses origin validation, honeypot and dwell-time checks, and expiring hashed-IP rate limits. OAuth states and sessions expire; raw IP addresses are not persisted for this control path.
Merchant payments
Project merchant credentials and products are separate from the user's Shipsite subscription. Product or price IDs are allowlisted. Provider webhooks are verified before they update the order ledger; a checkout button alone is not evidence of a working payment flow.