Features

Everything in Premia, by category

A premium SaaS stack — security, billing, multi-tenancy, audit, developer experience — all native.

Security

  • Strict CSP, HSTS 2-year preload, X-Frame-Options DENY
  • Signed URLs for password resets & email verification
  • Encrypted session cookies (AES-256-CBC)
  • CSRF tokens on every mutating form
  • Rate-limited login (5 attempts / 15 min / IP+email)
  • Per-IP failed-login monitoring + alerting
  • Strong password policy (12+ chars, mixed case, symbols)
  • Optional 2FA via TOTP (Google Authenticator compatible)
  • Recovery codes (single-use, encrypted)
  • Audit log on every mutating request

Multi-tenancy

  • Database-level isolation via global Eloquent scopes
  • tenant_id auto-filled on insert, immutable on update
  • Subdomain or path-based routing strategies
  • Per-user workspace switcher
  • Workspace-scoped roles: owner / admin / member / guest
  • Free-tier quotas enforced per-plan
  • Filament admin panel for global tenant management

Billing

  • Stripe Checkout (test + live modes)
  • Stripe Customer Portal integration
  • Subscription trials with metadata-rich webhooks
  • Invoice list + download
  • Webhook signature verification
  • Cancel-at-period-end flows
  • Plan upgrade / downgrade

Developer experience

  • Sanctum-powered REST API (v1)
  • Personal access tokens with scopes
  • Stripe-signed webhook receiver
  • Per-tenant audit log queryable via API
  • Clear migration history, no schema drift
  • Configurable CSP / HSTS via config file
  • README + deployment script for Hostinger