Security & compliance
Every request is authenticated, authorized, scoped to a tenant and recorded.
Argon2 password hashes, OTP verification, optional TOTP 2FA, lockout on repeated failures.
Granular RBAC: Super Admin, Admin, Dispatcher, Customer User. Permissions mapped to roles.
All operator data scoped by operator_id. Customers never see other tenants.
Immutable user/action/entity log for SOC 2 and regulatory review.
Refresh tokens with 30-minute TTL, IP and user-agent binding, revocable.
License expiry, subscription renewal and compliance warnings.
Three layers prevent accidental feature exposure across managed and self-managed customers.