Connections to OrangChat use encrypted HTTPS or WSS transport. Passwords are hashed with Argon2id rather than stored as readable passwords. Cloud-hosted message attachments and stored OAuth credentials are encrypted before storage. We also use access controls, short-lived access tokens, refresh-token rotation, optional two-factor authentication, rate limits, and restricted service permissions.