Security
CannaSage uses httpOnly cookie JWT authentication, optional TOTP 2FA, CSRF protection, encrypted credentials, and audit logging. Payments go through Stripe.
Controls
- TLS in transit; hashed passwords and httpOnly JWT cookies
- Optional TOTP 2FA and CSRF protection
- Encrypted connector credentials and audit logging
- PCI-compliant payments via Stripe — we do not store card numbers