Please report security issues privately rather than opening a public issue. For this portfolio repository, use the contact details listed on the repository owner's GitHub profile.
The demo has no default API key to keep local startup simple. Production deployments should set API_KEY, use HTTPS, rotate secrets, restrict CORS, apply network policies, and use a managed identity provider.