Our docs called the bot challenge mandatory. The env flag behind it defaulted to false in the deploy config, so a routine deploy would ship the gate down.

A public, unauthenticated form that writes to the database and sends email is a bot's favorite denial-of-service target. No single control is enough. The point is layering honeypot, Turnstile, rate limiting, and email verification so one layer failing doesn't sink the rest.
