Core principles
- ISR/SSG: Static delivery with periodic revalidation.
- Minimal client components: RSC first, interactive only where needed.
- Image pipeline:
next/imagewith AVIF/WebP and precisesizes. - Fonts:
next/fontwith subsets or self-hosted WOFF2. - Script diet: No unnecessary third-party tags; if analytics, keep it lightweight.
Security
- Strict CSP, HSTS,
SameSite=strictcookies (if needed). - Rate limiting + captcha on contact endpoint.
- No secrets in repo;
.envonly on the server.

