Encrypted at rest
Provider credentials and signing keys stored with AES-256-GCM
Two-factor access
TOTP multi-factor, with re-verification for privileged actions
Separated by tenant
Every query is scoped server-side; access is role-based, not UI-hidden