Two-factor authentication, genuinely strong
Three second factors: a code by SMS, an authenticator app (TOTP), or a passkey, which uses the device's fingerprint or face recognition and resists phishing. Every account is verified when it is created. Owners and administrators have no choice: on their first login, enabling 2FA is required.
- SMS, authenticator app or passkey
- 2FA mandatory for owners and administrators, enabled from the first login
- Account verification at sign-up
- Session reuse detection: all sessions revoked, an incident opened