PBKDF2-HMAC-SHA256 password hashing (600,000 iterations), never plaintext.
Every organization-scoped query is filtered server-side by organization ID — no cross-tenant read is reachable from the UI or API.
Strict Content-Security-Policy: no unsafe-inline, no unsafe-eval, no JavaScript at all on this platform's own web UI.
CSRF protection on every browser state-changing request; API requests use token auth instead (see Authentication).
API keys and webhook signing secrets are shown once at creation and stored only as a hash.
Support staff never have implicit access to your evidence — see the break-glass model in our internal operations documentation (summarized: security/audit/super-admin tiers only, reason required, always audited).