| Authentication with persistent session + idle timeout | ✅ active | Authentication |
| Per-user TOTP MFA (opt-in) | ✅ active | MFA |
| Active sessions visible + revocable by the user | ✅ active | Sessions |
| Per-company audit log with CSV export | ✅ active | Audit log |
| Anti brute force lockout + email notification | ✅ active | Anti brute force |
| Security HTTP headers (HSTS, CSP nonce, etc.) | ✅ active | Headers and CSP |
| Per-company IP allowlist (CIDR IPv4 + IPv6) | ✅ active | IP allowlist |
| Enterprise SSO (SAML 2.0 + OIDC via Stytch) | ✅ active | SSO |
| Secrets management (SSM Parameter Store + KMS) | ✅ active | Secrets management |
| AES-256-GCM encryption at rest + HMAC-SHA256 signatures | ✅ active (document signing opt-in per company) | Encryption and signatures |