Security

CannaSage uses httpOnly cookie JWT authentication, optional TOTP 2FA, CSRF protection, encrypted credentials, and audit logging. Payments go through Stripe.

Controls

  • TLS in transit; hashed passwords and httpOnly JWT cookies
  • Optional TOTP 2FA and CSRF protection
  • Encrypted connector credentials and audit logging
  • PCI-compliant payments via Stripe — we do not store card numbers