Security settings

  • MFA: TOTP with recovery codes; organisation enforcement applies to pages and every mutation; sensitive operations require a verified session.
  • SSO: SAML 2.0 (metadata URL/XML) or OIDC (Entra ID, Google Workspace, Keycloak, WorkOS); verified domains (DNS TXT), JIT provisioning, role mapping from groups/claims, enforced SSO, password login disabled per domain. SCIM is prepared behind the API token layer.
  • Approvals: two-person rule for awareness changes, reportability reversals, evidence deletion, submission amendments, owner/admin role changes, secret rotation, legal-hold release.
  • Auditor access: time-limited (≤ 180 days), scoped, read-only, fully logged.
  • Data & retention: retention categories, full organisation export (JSON, audit CSV, integrity manifest, evidence index), organisation deletion with 30-day cooling-off, owner-only, MFA-verified, with a description of what remains for legal reasons.

Last updated . This page describes the current release.