Security controls · C0123
How are session tokens protected?
In the pilot (v0.2.0, synthetic data)
Short answer
Sessions use random 256-bit tokens stored as hashes on the server, expiring after a fixed period and revocable. Tokens sit in browser session storage, which the review lists as an accepted low risk.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Is single sign-on available? Designed
- What happens to access when an employee leaves? Designed
- Can privileged users be created by one administrator alone? Pilot
- Is there a breached-password check? Open
See it in context: Sign-in, MFA and sessions · Search the help center · Ask a question