🔐Mandatory 2FA + HIBPTOTP enrollment is required before panel access. Passwords checked against breach lists on every set.
📋Append-only auditEvery state change written to merchant_audit_logs. Login attempts pruned after 90 days.