Create the first administrator from the temporary Netlify address before connecting the public custom domain. The customer-facing website remains unavailable until first setup is complete.
Provider credentials entered in the dashboard are encrypted before they are stored. The encryption key remains in Firebase Secret Manager as ORDIO_CREDENTIALS_KEY; never copy it into Firestore, an environment file or the source package. Reconnect any provider after changing this key.
When updating an earlier installation, the first secure provider check migrates its existing saved credentials into the encrypted format and removes the old plaintext fields.
Test Firestore and Storage rules before accepting real orders. App Check is not required for this release; callable and webhook rate limits provide a basic interim abuse control.