Payment and credential boundaries

Stripe handles full payment-card details and the authentication provider manages credentials outside Pygar application tables.

Two sensitive data types are kept outside Pygar's application tables:

  • Full payment-card details. Stripe handles payment details; Pygar stores billing identifiers and subscription state.
  • Authentication credentials. The authentication provider manages password credentials. Authentication password hashes are excluded from the Pygar account export.