Roles, mandatory 2FA, IP allowlist and API tokens are described in Security & access. How databases and volumes come back is covered under Backups & recovery.
Which events raise an alert, and where it goes, is shown under Notifications. Why an EU location matters for your supply chain is explained in Digital sovereignty.
Which questions an auditor asks and which evidence holds up is shown in NIS2 in Kubernetes operations; why Kubernetes Secrets alone are not enough, in Kubernetes Secrets: why Base64 is not encryption.