Protect the connection
HTTPS and supported mail protocols use authenticated TLS. Certificate verification remains enabled in runtime code.
transportSecurity is a chain of boundaries across transport, identity, sessions, recovery, application secrets, and mailbox operations.
No single control carries the whole security claim.
HTTPS and supported mail protocols use authenticated TLS. Certificate verification remains enabled in runtime code.
transportPasswords, MFA readiness, passkeys, bounded recovery, CSRF, and session rotation answer different threats.
identityReset tokens and backup codes are stored as hashes. Recoverable secrets require authenticated encryption.
dataEach layer answers a different risk: passwords establish a secret, authenticators add proof, passkeys resist phishing, and recovery methods must be verified before use.
protectedverified onlyrevocableauditableProtection is attached to a specific asset, mechanism, and visible outcome.
networkapplicationidentitydataserviceTransport, stored application secrets, mailbox storage, and end-to-end message encryption are separate layers. Claims must match the deployed architecture.
TLS protects supported network connections against passive interception.
Protection depends on database, application encryption, and mail-server deployment.
End-to-end encryption is claimed only where sender and recipient cryptography is implemented.
Each active public plan is joined to one current price while earlier Stripe Price mappings remain in history.