Authentication is delegated to your identity provider — two-factor, recovery and session security stay where you already manage them.
We store only the provider id, the email and the profile name — never a password.