ChangelogSOC 2 Phase 1 security baseline RS256-signed JWT access tokens with rotating refresh sessions. Redis AUTH, Postgres TLS, and per-request nonce CSP across all surfaces. Passkey and MFA enrollment flows fully wired through the production sign-in surface. Runtime config and integrationsCompliance hardening and dashboard polish