Security

PA includes application-level security controls, but operators still control the hosting environment.

Built-In Controls

Operator Responsibilities

Account Recovery

Use normal email reset when SMTP is configured. Public reset requests always return a generic response so they do not reveal whether an email exists. Codes expire after five minutes, are hashed in storage, are single-use, and are revoked after successful login.

When email or TOTP is unavailable, use the operator-only commands documented in Deployment. Password recovery preserves TOTP unless the operator explicitly supplies --reset-totp. Review admin.recovery_password_issued and admin.recovery_totp_reset events in the security audit trail after any recovery.

Reporting

Report vulnerabilities privately using the process in Security Policy.