A container is only as safe as the kernel features around it and the software inside it. This section tightens the first with capabilities, seccomp and a read-only filesystem, and checks the second with scanners, a software bill of materials and signatures, all on BookNest's own images.