Security

  • Argon2id password hashing
  • HTTP-only session cookies and CSRF protection
  • Server-side workspace membership checks
  • MFA foundation
  • Audit logging without content or secret leakage
  • Prepared quotas, reputation, and suspension architecture