Account security
- Two-factor authentication with authenticator apps (TOTP) and one-time recovery codes
- Strong password policy, including a compromised-password check on set
- Password changes require the current password and revoke every other active token
- Deactivating an account revokes all live tokens immediately
- Layered rate limiting on authentication and the API