Staff accounts require two-factor authentication. Login attempts lock after five failures.

Newsletter addresses are stored only after confirmation. Pending addresses sit behind a hashed token and expire. The list is not sold.

Public pages do not expose subscriber emails. Only administrators can read the list in the CMS.