We need to secure the backend with either a social auth or something. We also need to secure the API with a token based security measures. since the API might contain sensitive data