- [ ] Add middleware in `Program.cs` to redirect HTTP to HTTPS. - [ ] Use HSTS headers to enforce browser-level transport security. - [ ] Test browser and mobile behavior in staging environments.