Another pro-active addition to the application would be rate-limiting requests to the API. Stefan Prodan's **AspNetCoreRateLimit** looks like a really good option: [https://github.com/stefanprodan/AspNetCoreRateLimit/wiki](https://github.com/stefanprodan/AspNetCoreRateLimit/wiki)