Passwords are stored only as versioned, salted hashes.
Browser sessions use secure, HttpOnly cookies with CSRF and origin checks.
Password reset, recovery, and invitation delivery require configured messaging.
Application-managed MFA is planned and is not currently available.