Features
Everything in Premia, by category
A premium SaaS stack — security, billing, multi-tenancy, audit, developer experience — all native.
Security
- Strict CSP, HSTS 2-year preload, X-Frame-Options DENY
- Signed URLs for password resets & email verification
- Encrypted session cookies (AES-256-CBC)
- CSRF tokens on every mutating form
- Rate-limited login (5 attempts / 15 min / IP+email)
- Per-IP failed-login monitoring + alerting
- Strong password policy (12+ chars, mixed case, symbols)
- Optional 2FA via TOTP (Google Authenticator compatible)
- Recovery codes (single-use, encrypted)
- Audit log on every mutating request
Multi-tenancy
- Database-level isolation via global Eloquent scopes
- tenant_id auto-filled on insert, immutable on update
- Subdomain or path-based routing strategies
- Per-user workspace switcher
- Workspace-scoped roles: owner / admin / member / guest
- Free-tier quotas enforced per-plan
- Filament admin panel for global tenant management
Billing
- Stripe Checkout (test + live modes)
- Stripe Customer Portal integration
- Subscription trials with metadata-rich webhooks
- Invoice list + download
- Webhook signature verification
- Cancel-at-period-end flows
- Plan upgrade / downgrade
Developer experience
- Sanctum-powered REST API (v1)
- Personal access tokens with scopes
- Stripe-signed webhook receiver
- Per-tenant audit log queryable via API
- Clear migration history, no schema drift
- Configurable CSP / HSTS via config file
- README + deployment script for Hostinger