<?xml version="1.0" encoding="UTF-8"?>
<!--
  Sitemap for web crawlers (KAN-239).
  Lists ONLY the public, unauthenticated routes. Every other route is auth-gated
  (ProtectedRoute in frontend/src/app/router.tsx) and is intentionally omitted.
  Served from the site root because Vite copies frontend/public/ to the build output.

  https://app.tovarifinancial.com is a placeholder substituted at deploy time by scripts/deploy-frontend.sh
  with this environment's canonical app host (the FrontendUrl stack output) — e.g.
  https://app.tovarifinancial.com in dev, https://app.tovarifinancial.com in prod — so a
  single source file yields the correct per-environment absolute URLs.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://app.tovarifinancial.com/</loc>
    <lastmod>2026-07-13</lastmod>
    <changefreq>monthly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://app.tovarifinancial.com/login</loc>
    <lastmod>2026-07-13</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://app.tovarifinancial.com/signup</loc>
    <lastmod>2026-07-13</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://app.tovarifinancial.com/forgot-password</loc>
    <lastmod>2026-07-13</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
