
Accounts
Secure sessions and sign-in protections
Passwords are hashed, login/register/reset routes are throttled, email verification and session revocation are supported, MFA/TOTP readiness exists, mobile tokens use secure storage, inactive users are blocked, and security events are recorded without raw secrets.

