Staff accounts require two-factor authentication. Login attempts lock after five failures.
Newsletter addresses are stored only after confirmation. Pending addresses sit behind a hashed token and expire. The list is not sold.
Public pages do not expose subscriber emails. Only administrators can read the list in the CMS.