Secure by default
Your account is protected
Hashed credentials
Passwords use salted scrypt hashing and are never stored in plain text.
Two-factor authentication
TOTP authenticator support plus Hubtel SMS verification and recovery codes.
Server-side authorisation
Roles and permissions are resolved on the server, never from the browser.
Audit logging
Sensitive actions are recorded with actor, resource, IP and result.
Rate limiting
Login, OTP and submission endpoints are protected against brute force.
